CVE-2024-11147
PoC ×2—CVSS 4.0
7.0 high
EPSS
<1%p34
Published
()
Modified
Description
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
- Vendors
- ecovacs
- Products
- deebot 900 firmware, deebot n8 firmware, deebot t8 firmware, deebot n9 firmware, deebot t9 firmware, deebot n10 firmware, deebot t10 firmware, deebot x1 firmware, deebot t20 firmware, deebot x2 firmware, goat g1 firmware, airbot z1 firmware
- Weakness
- CWE-798
- Vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.