CVE-2024-52331
PoC ×2—CVSS 4.0
7.7 high
EPSS
<1%p12
Published
()
Modified
Description
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
- Vendors
- ecovacs
- Products
- deebot 900 firmware, deebot n8 firmware, deebot t8 firmware, deebot n9 firmware, deebot t9 firmware, deebot n10 firmware, deebot t10 firmware, deebot x1 firmware, deebot t20 firmware, deebot x2 firmware, goat g1 firmware, airbot z1 firmware
- Weakness
- CWE-327, CWE-494, CWE-1391
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.