Unrated severityNVD Advisory· Published Sep 5, 2025· Updated Sep 8, 2025
ECOVACS Vacuum and Base Station accept unsigned firmware
CVE-2025-30199
Description
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
Affected products
5- ECOVACS/DEEBOT T10 Seriesv5Range: *
- ECOVACS/DEEBOT T20 Seriesv5Range: *
- ECOVACS/DEEBOT T30 Seriesv5Range: *
- ECOVACS/DEEBOT X1 Seriesv5Range: *
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.