HIGH · 7.2

CVE-2025-30199

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

Vulnerability Description

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
EcovacsDeebot X1S Pro Firmware< 2.5.38
EcovacsDeebot X1S Pro-
EcovacsDeebot X1 Pro Omni Firmware< 2.5.38
EcovacsDeebot X1 Pro Omni-
EcovacsDeebot X1 Omni Firmware< 2.4.45
EcovacsDeebot X1 Omni-
EcovacsDeebot X1 Turbo Firmware< 2.5.38
EcovacsDeebot X1 Turbo-
EcovacsDeebot T10 Firmware< 1.11.0
EcovacsDeebot T10-
EcovacsDeebot T10 Omni Firmware< 1.11.0
EcovacsDeebot T10 Omni-
EcovacsDeebot T10 Plus Firmware< 1.11.0
EcovacsDeebot T10 Plus-
EcovacsDeebot T10 Turbo Firmware< 1.11.0
EcovacsDeebot T10 Turbo-
EcovacsDeebot T20 Omni Firmware< 1.25.0
EcovacsDeebot T20 Omni-
EcovacsDeebot T20 Pro Plus Firmware< 1.25.0
EcovacsDeebot T20 Pro Plus-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-30199?

CVE-2025-30199 is a vulnerability with a CVSS score of 7.2 (HIGH). ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

How severe is CVE-2025-30199?

CVE-2025-30199 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-30199?

Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Deebot X1S Pro Firmware, Ecovacs Deebot X1S Pro, Ecovacs Deebot X1 Pro Omni Firmware, Ecovacs Deebot X1 Pro Omni, Ecovacs Deebot X1 Omni Firmware.