Vulnerability Description
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecovacs | Deebot 900 Firmware | - |
| Ecovacs | Deebot 900 | - |
| Ecovacs | Deebot N8 Firmware | - |
| Ecovacs | Deebot N8 | - |
| Ecovacs | Deebot T8 Firmware | - |
| Ecovacs | Deebot T8 | - |
| Ecovacs | Deebot N9 Firmware | - |
| Ecovacs | Deebot N9 | - |
| Ecovacs | Deebot T9 Firmware | - |
| Ecovacs | Deebot T9 | - |
| Ecovacs | Deebot N10 Firmware | - |
| Ecovacs | Deebot N10 | - |
| Ecovacs | Deebot T10 Firmware | - |
| Ecovacs | Deebot T10 | - |
| Ecovacs | Deebot X1 Firmware | - |
| Ecovacs | Deebot X1 | - |
| Ecovacs | Deebot T20 Firmware | - |
| Ecovacs | Deebot T20 | - |
| Ecovacs | Deebot X2 Firmware | - |
| Ecovacs | Deebot X2 | - |
Related Weaknesses (CWE)
References
- https://builder.dontvacuum.me/ecopassword.phpProduct
- https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdfExploitThird Party Advisory
- https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdfExploitThird Party Advisory
FAQ
What is CVE-2024-11147?
CVE-2024-11147 is a vulnerability with a CVSS score of 7.6 (HIGH). ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
How severe is CVE-2024-11147?
CVE-2024-11147 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-11147?
Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Deebot 900 Firmware, Ecovacs Deebot 900, Ecovacs Deebot N8 Firmware, Ecovacs Deebot N8, Ecovacs Deebot T8 Firmware.