High severity7.4NVD Advisory· Published Jan 23, 2025· Updated Jun 17, 2026
CVE-2024-52329
CVE-2024-52329
Description
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
Affected products
2- ECOVACS/ECOVACS HOMEv5Range: 0
Patches
Vulnerability mechanics
References
3- dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdfnvdExploitThird Party Advisory
- dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdfnvdExploitThird Party Advisory
- www.ecovacs.com/global/userhelp/dsa20241217001nvdVendor Advisory
News mentions
0No linked articles in our index yet.