CRITICAL · 9.6

CVE-2024-52325

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

Vulnerability Description

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

CVSS Score

9.6

CRITICAL

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
EcovacsGoat G1-2000 Firmware< 1.36.187
EcovacsGoat G1-2000-
EcovacsGoat G1 Firmware< 1.36.187
EcovacsGoat G1-
EcovacsGoat G1-800 Firmware< 1.36.187
EcovacsGoat G1-800-
EcovacsGx-600 Firmware< 1.2.120
EcovacsGx-600-
EcovacsDeebot X2 Omni Firmware< 1.76.6
EcovacsDeebot X2 Omni-
EcovacsDeebot X2 Combo Firmware< 1.81.10
EcovacsDeebot X2 Combo-
EcovacsDeebot X2S Firmware< 1.49.0
EcovacsDeebot X2S-
EcovacsDeebot X5 Pro Firmware< 1.70.0
EcovacsDeebot X5 Pro-
EcovacsDeebot X5 Pro Plus Firmware< 1.38.0
EcovacsDeebot X5 Pro Plus-
EcovacsDeebot X5 Pro Ultra Firmware< 1.17.0
EcovacsDeebot X5 Pro Ultra-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-52325?

CVE-2024-52325 is a vulnerability with a CVSS score of 9.6 (CRITICAL). ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

How severe is CVE-2024-52325?

CVE-2024-52325 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2024-52325?

Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Goat G1-2000 Firmware, Ecovacs Goat G1-2000, Ecovacs Goat G1 Firmware, Ecovacs Goat G1, Ecovacs Goat G1-800 Firmware.