Description

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

INFO

Published Date :

2025-01-23T16:36:50.128Z

Last Modified :

2025-02-12T20:41:28.969Z

Source :

cisa-cg
AFFECTED PRODUCTS

The following products are affected by CVE-2024-52330 vulnerability.

Vendors Products
Ecovacs
  • Deebot T10
  • Deebot T10 Firmware
  • Deebot T10 Omni
  • Deebot T10 Omni Firmware
  • Deebot T10 Plus
  • Deebot T10 Plus Firmware
  • Deebot T10 Turbo
  • Deebot T10 Turbo Firmware
  • Deebot X1
  • Deebot X1 Firmware
  • Deebot X1 Omni
  • Deebot X1 Omni Firmware
  • Deebot X1 Plus
  • Deebot X1 Plus Firmware
  • Deebot X1 Pro Omni
  • Deebot X1 Pro Omni Firmware
  • Deebot X1 Turbo
  • Deebot X1 Turbo Firmware
  • Deebot X1e Omni
  • Deebot X1e Omni Firmware
  • Deebot X1s Pro
  • Deebot X1s Pro Firmware
  • Deebot X1s Pro Plus
  • Deebot X1s Pro Plus Firmware
  • Deebot X2 Combo
  • Deebot X2 Combo Firmware
  • Deebot X2 Omni
  • Deebot X2 Omni Firmware
  • Deebot X2 Pro
  • Deebot X2 Pro Firmware
  • Deebot X2s
  • Deebot X2s Firmware
  • Deebot X5 Pro
  • Deebot X5 Pro Firmware
  • Deebot X5 Pro Plus
  • Deebot X5 Pro Plus Firmware
  • Deebot X5 Pro Ultra
  • Deebot X5 Pro Ultra Firmware
  • Mate X
  • Mate X Firmware
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact