VYPR
High severity7.4NVD Advisory· Published Jan 23, 2025· Updated Jun 17, 2026

CVE-2024-52329

CVE-2024-52329

Description

ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.

Affected products

4
  • Ecovacs/Home2 versions
    cpe:2.3:a:ecovacs:home:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:ecovacs:home:*:*:*:*:*:android:*:*range: <3.0.0
    • cpe:2.3:a:ecovacs:home:*:*:*:*:*:iphone_os:*:*range: <3.0.0
  • ECOVACS/ECOVACS HOMEv5
    Range: 0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.