VYPR

lawnmowers and vacuums

by Ecovacs

CVEs (5)

  • CVE-2024-52325CriJan 23, 2025
    risk 0.63cvss 9.6epss 0.03

    ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

  • CVE-2024-11147HigJan 23, 2025
    risk 0.49cvss 7.6epss 0.00

    ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.

  • CVE-2024-52330HigJan 23, 2025
    risk 0.48cvss 7.4epss 0.00

    ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

  • CVE-2024-52327MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.00

    The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

  • CVE-2024-12078MedJan 23, 2025
    risk 0.41cvss 6.3epss 0.00

    ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.