Impact
The vulnerability arises from improper validation of server certificates in the ECOVACS PRO Android and iOS applications. As a result, an attacker who can interpose on network traffic may supply a forged certificate and intercept or alter data exchanged between the app and the authorized backend. The weakness is a failure to authenticate the server, which can lead to confidentiality and integrity violations.
Affected Systems
Vulnerable systems include users running the ECOVACS PRO app on Android or iOS devices. The issue applies to all installations that rely on the app’s default certificate validation logic, regardless of firmware version, since the description does not list specific affected app releases.
Risk and Exploitability
The CVSS score of 2.3 indicates a low technical severity, but the lack of strong server authentication removes a crucial layer of security. Because the EPSS score is not available, the probability of exploitation is uncertain, yet the possibility remains if an attacker can supply a mitm proxy. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. The likely attack vector is a network‑level MITM, exploiting the lack of certificate validation to alter or capture communication.
OpenCVE Enrichment