CVE Feed

    Dashboard / CVE / CVE-2024-52328

    CVE-2024-52328

    ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.

    Published:Jan 23, 2025
    Last Modified:Sep 23, 2025
    EPS:Jan 23, 2025
    EPSS Score:0.00025
    CVSS Score:2.3

    Affected Products

    Vendor
    Ecovacs
    Product
    Airbot Andy
    Vendor
    Ecovacs
    Product
    Airbot Andy Firmware
    Vendor
    Ecovacs
    Product
    Airbot Ava
    Vendor
    Ecovacs
    Product
    Airbot Ava Firmware
    Vendor
    Ecovacs
    Product
    Airbot Z1
    Vendor
    Ecovacs
    Product
    Airbot Z1 Firmware
    Vendor
    Ecovacs
    Product
    Deebot 900
    Vendor
    Ecovacs
    Product
    Deebot 900 Firmware
    Vendor
    Ecovacs
    Product
    Deebot N10
    Vendor
    Ecovacs
    Product
    Deebot N10 Firmware
    Vendor
    Ecovacs
    Product
    Deebot N8
    Vendor
    Ecovacs
    Product
    Deebot N8 Firmware
    Vendor
    Ecovacs
    Product
    Deebot N9
    Vendor
    Ecovacs
    Product
    Deebot N9 Firmware
    Vendor
    Ecovacs
    Product
    Deebot T10
    Vendor
    Ecovacs
    Product
    Deebot T10 Firmware
    Vendor
    Ecovacs
    Product
    Deebot T20
    Vendor
    Ecovacs
    Product
    Deebot T20 Firmware
    Vendor
    Ecovacs
    Product
    Deebot T8
    Vendor
    Ecovacs
    Product
    Deebot T8 Firmware
    Vendor
    Ecovacs
    Product
    Deebot T9
    Vendor
    Ecovacs
    Product
    Deebot T9 Firmware
    Vendor
    Ecovacs
    Product
    Deebot X1
    Vendor
    Ecovacs
    Product
    Deebot X1 Firmware
    Vendor
    Ecovacs
    Product
    Deebot X2
    Vendor
    Ecovacs
    Product
    Deebot X2 Firmware
    Vendor
    Ecovacs
    Product
    Goat G1
    Vendor
    Ecovacs
    Product
    Goat G1 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High