CVE-2024-52327
6.5MEDIUMThe cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
Published: 1/23/2025Updated: 9/23/2025
Description
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
AI AnalysisPowered by AI
Affected Products
ecovacshome
ecovacshome
References
- https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdfExploitThird Party Advisory
- https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdfExploitThird Party Advisory
- https://www.ecovacs.com/global/userhelp/dsa20241217002Vendor Advisory