ZeroHour

CVE-2024-52331

PoC ×2
CVSS 4.0
7.7 high
EPSS
<1%p12
Published
()
Modified
Description

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.

Vendors
ecovacs
Products
deebot 900 firmware, deebot n8 firmware, deebot t8 firmware, deebot n9 firmware, deebot t9 firmware, deebot n10 firmware, deebot t10 firmware, deebot x1 firmware, deebot t20 firmware, deebot x2 firmware, goat g1 firmware, airbot z1 firmware
Weakness
CWE-327, CWE-494, CWE-1391
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.