Vulnerability Description
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecovacs | Deebot 900 Firmware | - |
| Ecovacs | Deebot 900 | - |
| Ecovacs | Deebot N8 Firmware | - |
| Ecovacs | Deebot N8 | - |
| Ecovacs | Deebot T8 Firmware | - |
| Ecovacs | Deebot T8 | - |
| Ecovacs | Deebot N9 Firmware | - |
| Ecovacs | Deebot N9 | - |
| Ecovacs | Deebot T9 Firmware | - |
| Ecovacs | Deebot T9 | - |
| Ecovacs | Deebot N10 Firmware | - |
| Ecovacs | Deebot N10 | - |
| Ecovacs | Deebot T10 Firmware | - |
| Ecovacs | Deebot T10 | - |
| Ecovacs | Deebot X1 Firmware | - |
| Ecovacs | Deebot X1 | - |
| Ecovacs | Deebot T20 Firmware | - |
| Ecovacs | Deebot T20 | - |
| Ecovacs | Deebot X2 Firmware | - |
| Ecovacs | Deebot X2 | - |
Related Weaknesses (CWE)
References
- https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdfExploitThird Party Advisory
- https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.htmlExploitThird Party Advisory
FAQ
What is CVE-2024-52331?
CVE-2024-52331 is a vulnerability with a CVSS score of 7.5 (HIGH). ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and instal...
How severe is CVE-2024-52331?
CVE-2024-52331 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-52331?
Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Deebot 900 Firmware, Ecovacs Deebot 900, Ecovacs Deebot N8 Firmware, Ecovacs Deebot N8, Ecovacs Deebot T8 Firmware.