CVE-2024-52330
Published Jan 23, 2025ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
Vendor/product archive
2 CVEs tagged to ecovacs / deebot_x5_pro_plus — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.