Vulnerability Description
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecovacs | Goat G1-2000 Firmware | < 1.36.187 |
| Ecovacs | Goat G1-2000 | - |
| Ecovacs | Goat G1 Firmware | < 1.36.187 |
| Ecovacs | Goat G1 | - |
| Ecovacs | Goat G1-800 Firmware | < 1.36.187 |
| Ecovacs | Goat G1-800 | - |
| Ecovacs | Gx-600 Firmware | < 1.2.120 |
| Ecovacs | Gx-600 | - |
| Ecovacs | Deebot X2 Omni Firmware | < 1.76.6 |
| Ecovacs | Deebot X2 Omni | - |
| Ecovacs | Deebot X2 Combo Firmware | < 1.81.10 |
| Ecovacs | Deebot X2 Combo | - |
| Ecovacs | Deebot X2S Firmware | < 1.49.0 |
| Ecovacs | Deebot X2S | - |
| Ecovacs | Deebot X5 Pro Firmware | < 1.70.0 |
| Ecovacs | Deebot X5 Pro | - |
| Ecovacs | Deebot X5 Pro Plus Firmware | < 1.38.0 |
| Ecovacs | Deebot X5 Pro Plus | - |
| Ecovacs | Deebot X5 Pro Ultra Firmware | < 1.17.0 |
| Ecovacs | Deebot X5 Pro Ultra | - |
Related Weaknesses (CWE)
References
- https://dontvacuum.me/talks/DEFCON32/DEFCON32_reveng_hacking_ecovacs_robots.pdfExploitThird Party Advisory
- https://www.ecovacs.com/global/userhelp/dsa20241119Vendor Advisory
- https://www.ecovacs.com/global/userhelp/dsa20241130001Vendor Advisory
- https://youtu.be/_wUsM0Mlenc?t=2041Exploit
FAQ
What is CVE-2024-52325?
CVE-2024-52325 is a vulnerability with a CVSS score of 9.6 (CRITICAL). ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
How severe is CVE-2024-52325?
CVE-2024-52325 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-52325?
Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Goat G1-2000 Firmware, Ecovacs Goat G1-2000, Ecovacs Goat G1 Firmware, Ecovacs Goat G1, Ecovacs Goat G1-800 Firmware.