CVE-2024-52325
5.8
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 9119a7d8-5eab-497f-8521-727c672e3725 (Secondary)
Description
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Affected (12)
Products: Ecovacs: Goat G1 2000 Firmware, Goat G1 Firmware, Goat G1 800 Firmware, Gx 600 Firmware, Deebot X2 Omni Firmware, Deebot X2 Combo Firmware, Deebot X2s Firmware, Deebot X5 Pro Firmware, Deebot X5 Pro Plus Firmware, Deebot X5 Pro Ultra Firmware, Deebot T30 Omni Firmware, Deebot T30s Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.36.187 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Goat G1 2000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.36.187 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Goat G1 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.36.187 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Goat G1 800 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.120 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Gx 600 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.76.6 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X2 Omni | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.81.10 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X2 Combo | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.49.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X2s | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.70.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X5 Pro | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.38.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X5 Pro Plus | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.17.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X5 Pro Ultra | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.93.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T30 Omni | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.95.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T30s | All versions |
References (4)
Source: 9119a7d8-5eab-497f-8521-727c672e3725
ExploitThird Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Timeline
No history available yet.