CVE-2024-12078
MEDIUMECOVACS Robot Firmware - Shared BLE Key Robot Control
Title source: manualDescription
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf
Scores
CVSS v3
6.3
EPSS
0.0031
EPSS Percentile
22.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-321
Status
published
Products (14)
ecovacs/airbot_andy_firmware
ecovacs/airbot_ava_firmware
ecovacs/airbot_z1_firmware
ecovacs/deebot_900_firmware
ecovacs/deebot_n10_firmware
ecovacs/deebot_n8_firmware
ecovacs/deebot_n9_firmware
ecovacs/deebot_t10_firmware
ecovacs/deebot_t20_firmware
ecovacs/deebot_t8_firmware
... and 4 more
Published
Jan 23, 2025
Tracked Since
Feb 18, 2026