CVE-2025-30200
2.3
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 9119a7d8-5eab-497f-8521-727c672e3725 (Secondary)
Description
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
Affected (14)
Products: Ecovacs: Deebot X1s Pro Firmware, Deebot X1 Pro Omni Firmware, Deebot X1 Omni Firmware, Deebot X1 Turbo Firmware, Deebot T10 Firmware, Deebot T10 Omni Firmware, Deebot T10 Plus Firmware, Deebot T10 Turbo Firmware, Deebot T20 Omni Firmware, Deebot T20 Pro Plus Firmware, Deebot T20 Pro Firmware, Deebot T30 Omni Firmware, Deebot T30s Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.38 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.38 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X1 Pro Omni | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.45 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X1 Omni | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.38 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X1 Turbo | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.45 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot X1s Pro | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.11.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T10 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.11.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T10 Omni | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.11.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T10 Plus | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.11.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T10 Turbo | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.25.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T20 Omni | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.25.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T20 Pro Plus | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.25.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T20 Pro | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.100.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T30 Omni | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.100.0 |
| Running on/with | Platform Versions |
|---|---|
Ecovacs Deebot T30s | All versions |
Related CWEs
References (3)
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party AdvisoryUS Government Resource
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory
Timeline
No history available yet.