CVE-2024-52325
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Published:Jan 23, 2025
Last Modified:Sep 23, 2025
EPS:Jan 23, 2025
EPSS Score:0.02401
CVSS Score:9.6
Affected Products
Vendor
Product
Action
Vendor
Ecovacs
Product
Deebot T30 Omni
Ecovacs
Deebot T30 Omni
Vendor
Ecovacs
Product
Deebot T30 Omni Firmware
Ecovacs
Deebot T30 Omni Firmware
Vendor
Ecovacs
Product
Deebot T30s
Ecovacs
Deebot T30s
Vendor
Ecovacs
Product
Deebot T30s Firmware
Ecovacs
Deebot T30s Firmware
Vendor
Ecovacs
Product
Deebot X2 Combo
Ecovacs
Deebot X2 Combo
Vendor
Ecovacs
Product
Deebot X2 Combo Firmware
Ecovacs
Deebot X2 Combo Firmware
Vendor
Ecovacs
Product
Deebot X2 Omni
Ecovacs
Deebot X2 Omni
Vendor
Ecovacs
Product
Deebot X2 Omni Firmware
Ecovacs
Deebot X2 Omni Firmware
Vendor
Ecovacs
Product
Deebot X2s
Ecovacs
Deebot X2s
Vendor
Ecovacs
Product
Deebot X2s Firmware
Ecovacs
Deebot X2s Firmware
Vendor
Ecovacs
Product
Deebot X5 Pro
Ecovacs
Deebot X5 Pro
Vendor
Ecovacs
Product
Deebot X5 Pro Firmware
Ecovacs
Deebot X5 Pro Firmware
Vendor
Ecovacs
Product
Deebot X5 Pro Plus
Ecovacs
Deebot X5 Pro Plus
Vendor
Ecovacs
Product
Deebot X5 Pro Plus Firmware
Ecovacs
Deebot X5 Pro Plus Firmware
Vendor
Ecovacs
Product
Deebot X5 Pro Ultra
Ecovacs
Deebot X5 Pro Ultra
Vendor
Ecovacs
Product
Deebot X5 Pro Ultra Firmware
Ecovacs
Deebot X5 Pro Ultra Firmware
Vendor
Ecovacs
Product
Goat G1
Ecovacs
Goat G1
Vendor
Ecovacs
Product
Goat G1-2000
Ecovacs
Goat G1-2000
Vendor
Ecovacs
Product
Goat G1-2000 Firmware
Ecovacs
Goat G1-2000 Firmware
Vendor
Ecovacs
Product
Goat G1-800
Ecovacs
Goat G1-800
Vendor
Ecovacs
Product
Goat G1-800 Firmware
Ecovacs
Goat G1-800 Firmware
Vendor
Ecovacs
Product
Goat G1 Firmware
Ecovacs
Goat G1 Firmware
Vendor
Ecovacs
Product
Gx-600
Ecovacs
Gx-600
Vendor
Ecovacs
Product
Gx-600 Firmware
Ecovacs
Gx-600 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
