CVE-2024-52327

MEDIUM

ECOVACS - Auth Bypass

Title source: llm
STIX 2.1

Description

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 29.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-603 CWE-807
Status published
Products (1)
ecovacs/home < 3.0.2 (2 CPE variants)
Published Jan 23, 2025
Tracked Since Feb 18, 2026