Description
Android and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.
Published: 2026-08-10
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper validation of server certificates in the ECOVACS PRO Android and iOS applications. As a result, an attacker who can interpose on network traffic may supply a forged certificate and intercept or alter data exchanged between the app and the authorized backend. The weakness is a failure to authenticate the server, which can lead to confidentiality and integrity violations.

Affected Systems

Vulnerable systems include users running the ECOVACS PRO app on Android or iOS devices. The issue applies to all installations that rely on the app’s default certificate validation logic, regardless of firmware version, since the description does not list specific affected app releases.

Risk and Exploitability

The CVSS score of 2.3 indicates a low technical severity, but the lack of strong server authentication removes a crucial layer of security. Because the EPSS score is not available, the probability of exploitation is uncertain, yet the possibility remains if an attacker can supply a mitm proxy. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. The likely attack vector is a network‑level MITM, exploiting the lack of certificate validation to alter or capture communication.

Generated by OpenCVE AI on August 10, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ECOVACS PRO app to the latest version available from the official Google Play or Apple App Store, as the vendor has released fixes that enforce strict server certificate validation.
  • Ensure your device’s operating system and network components are current, which helps maintain updated root trust stores and network security policies.
  • If you operate in a corporate or controlled environment, configure the network or firewall to block or flag any unexpected or self‑signed SSL/TLS certificates presented to the ECOVACS PRO app, thereby reducing the risk of successful man‑in‑the‑middle attacks.

Generated by OpenCVE AI on August 10, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Server Certificate Validation in ECOVACS PRO Apps

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T08:08:54.747Z

Reserved: 2026-07-27T00:45:20.457Z

Link: CVE-2026-66410

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T09:30:03Z

Weaknesses
  • CWE-295

    Improper Certificate Validation