Description
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Published: 2025-01-23
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-46255 ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
History

Tue, 23 Sep 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs
Ecovacs deebot T30 Omni
Ecovacs deebot T30 Omni Firmware
Ecovacs deebot T30s
Ecovacs deebot T30s Firmware
Ecovacs deebot X2 Combo
Ecovacs deebot X2 Combo Firmware
Ecovacs deebot X2 Omni
Ecovacs deebot X2 Omni Firmware
Ecovacs deebot X2s
Ecovacs deebot X2s Firmware
Ecovacs deebot X5 Pro
Ecovacs deebot X5 Pro Firmware
Ecovacs deebot X5 Pro Plus
Ecovacs deebot X5 Pro Plus Firmware
Ecovacs deebot X5 Pro Ultra
Ecovacs deebot X5 Pro Ultra Firmware
Ecovacs goat G1
Ecovacs goat G1-2000
Ecovacs goat G1-2000 Firmware
Ecovacs goat G1-800
Ecovacs goat G1-800 Firmware
Ecovacs goat G1 Firmware
Ecovacs gx-600
Ecovacs gx-600 Firmware
CPEs cpe:2.3:h:ecovacs:deebot_t30_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30s:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1-2000:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1-800:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:gx-600:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t30_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1-2000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1-800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:gx-600_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ecovacs
Ecovacs deebot T30 Omni
Ecovacs deebot T30 Omni Firmware
Ecovacs deebot T30s
Ecovacs deebot T30s Firmware
Ecovacs deebot X2 Combo
Ecovacs deebot X2 Combo Firmware
Ecovacs deebot X2 Omni
Ecovacs deebot X2 Omni Firmware
Ecovacs deebot X2s
Ecovacs deebot X2s Firmware
Ecovacs deebot X5 Pro
Ecovacs deebot X5 Pro Firmware
Ecovacs deebot X5 Pro Plus
Ecovacs deebot X5 Pro Plus Firmware
Ecovacs deebot X5 Pro Ultra
Ecovacs deebot X5 Pro Ultra Firmware
Ecovacs goat G1
Ecovacs goat G1-2000
Ecovacs goat G1-2000 Firmware
Ecovacs goat G1-800
Ecovacs goat G1-800 Firmware
Ecovacs goat G1 Firmware
Ecovacs gx-600
Ecovacs gx-600 Firmware

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Description ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Title ECOVACS robot lawnmowers and vacuums command injection
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Ecovacs Deebot T30 Omni Deebot T30 Omni Firmware Deebot T30s Deebot T30s Firmware Deebot X2 Combo Deebot X2 Combo Firmware Deebot X2 Omni Deebot X2 Omni Firmware Deebot X2s Deebot X2s Firmware Deebot X5 Pro Deebot X5 Pro Firmware Deebot X5 Pro Plus Deebot X5 Pro Plus Firmware Deebot X5 Pro Ultra Deebot X5 Pro Ultra Firmware Goat G1 Goat G1-2000 Goat G1-2000 Firmware Goat G1-800 Goat G1-800 Firmware Goat G1 Firmware Gx-600 Gx-600 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2025-02-12T20:41:26.651Z

Reserved: 2024-11-08T01:06:02.404Z

Link: CVE-2024-52325

cve-icon Vulnrichment

Updated: 2025-02-12T20:34:47.477Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-23T16:15:35.943

Modified: 2025-09-23T17:35:35.463

Link: CVE-2024-52325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses