CVE-2024-52327

MEDIUM

ECOVACS Home < 3.0.2 - Authenticated PIN Bypass for Live Video Feed Access

Title source: llm
STIX 2.1

Description

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

Scores

CVSS v3 6.5
EPSS 0.0044
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-603 CWE-807
Status published
Products (1)
ecovacs/home < 3.0.2 (2 CPE variants)
Published Jan 23, 2025
Tracked Since Feb 18, 2026