CVE-2024-52327
6.5MEDIUMThe cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
Publicado: 1/23/2025Actualizado: 9/23/2025
Descripción
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
Análisis IAImpulsado por IA
Productos Afectados
ecovacshome
ecovacshome
Referencias
- https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdfExploitThird Party Advisory
- https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdfExploitThird Party Advisory
- https://www.ecovacs.com/global/userhelp/dsa20241217002Vendor Advisory