High severity7.2NVD Advisory· Published Sep 5, 2025· Updated Jun 17, 2026
CVE-2025-30199
CVE-2025-30199
Description
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:*Range: <1.11.0
- cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:*Range: <1.11.0
- cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:*Range: <1.11.0
- cpe:2.3:o:ecovacs:deebot_t20_omni_firmware:*:*:*:*:*:*:*:*Range: <1.25.0
- cpe:2.3:o:ecovacs:deebot_t20_pro_firmware:*:*:*:*:*:*:*:*Range: <1.25.0
- cpe:2.3:o:ecovacs:deebot_t20_pro_plus_firmware:*:*:*:*:*:*:*:*Range: <1.25.0
- cpe:2.3:o:ecovacs:deebot_t30_omni_firmware:*:*:*:*:*:*:*:*Range: <1.100.0
- cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:*Range: <2.4.45
- cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:*Range: <2.5.38
- cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:*Range: <2.5.38
- cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*Range: <2.5.38
- ECOVACS/DEEBOT T10 Seriesv5Range: *
- ECOVACS/DEEBOT T20 Seriesv5Range: *
- ECOVACS/DEEBOT T30 Seriesv5Range: *
- ECOVACS/DEEBOT X1 Seriesv5Range: *
Patches
Vulnerability mechanics
References
3- github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-135-19.jsonnvdThird Party Advisory
- www.cisa.gov/news-events/ics-advisories/icsa-25-135-19nvdThird Party AdvisoryUS Government Resource
- www.cve.org/CVERecordnvdThird Party Advisory
News mentions
0No linked articles in our index yet.