Description
Android and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.
Published: 2026-08-10
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper validation of server certificates in the ECOVACS PRO Android and iOS applications. As a result, an attacker who can interpose on network traffic may supply a forged certificate and intercept or alter data exchanged between the app and the authorized backend. The weakness is a failure to authenticate the server, which can lead to confidentiality and integrity violations.

Affected Systems

Vulnerable systems include users running the ECOVACS PRO app on Android or iOS devices. The issue applies to all installations that rely on the app’s default certificate validation logic, regardless of firmware version, since the description does not list specific affected app releases.

Risk and Exploitability

The CVSS score of 2.3 indicates a low technical severity, but the lack of strong server authentication removes a crucial layer of security. Because the EPSS score is not available, the probability of exploitation is uncertain, yet the possibility remains if an attacker can supply a mitm proxy. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. The likely attack vector is a network‑level MITM, exploiting the lack of certificate validation to alter or capture communication.

Generated by OpenCVE AI on August 10, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ECOVACS PRO app to the latest version available from the official Google Play or Apple App Store, as the vendor has released fixes that enforce strict server certificate validation.
  • Ensure your device’s operating system and network components are current, which helps maintain updated root trust stores and network security policies.
  • If you operate in a corporate or controlled environment, configure the network or firewall to block or flag any unexpected or self‑signed SSL/TLS certificates presented to the ECOVACS PRO app, thereby reducing the risk of successful man‑in‑the‑middle attacks.

Generated by OpenCVE AI on August 10, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs Robotics
Ecovacs Robotics android App "ecovacs Pro"
Ecovacs Robotics ios App "ecovacs Pro"
Vendors & Products Ecovacs Robotics
Ecovacs Robotics android App "ecovacs Pro"
Ecovacs Robotics ios App "ecovacs Pro"

Mon, 10 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Server Certificate Validation in ECOVACS PRO Apps

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ecovacs Robotics Android App "ecovacs Pro" Ios App "ecovacs Pro"
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T11:11:44.211Z

Reserved: 2026-07-27T00:45:20.457Z

Link: CVE-2026-66410

cve-icon Vulnrichment

Updated: 2026-08-10T11:11:39.953Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T09:17:23.350

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-66410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:25:41Z

Weaknesses
  • CWE-295

    Improper Certificate Validation