Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ECOVACS | GOAT G1 | 0 ~ 1.36.187 | - | |
| ECOVACS | GOAT G1-800 | 0 ~ 1.36.187 | - | |
| ECOVACS | DEEBOT X2S | 0 ~ 1.49.0 | - | |
| ECOVACS | DEEBOT X5 PRO | 0 ~ 1.70.0 | - | |
| ECOVACS | DEEBOT X5 PRO PLUS | 0 ~ 1.38.0 | - | |
| ECOVACS | DEEBOT T30 OMNI | 0 ~ 1.93.0 | - | |
| ECOVACS | DEEBOT T30S | 0 ~ 1.95.0 | - | |
| ECOVACS | GOAT G1-2000 | 0 ~ 1.36.187 | - | |
| ECOVACS | GOAT GX-600 | 0 ~ 1.2.120 | - | |
| ECOVACS | DEEBOT X2 OMNI | 0 ~ 1.76.6 | - | |
| ECOVACS | DEEBOT X2 COMBO | 0 ~ 1.81.10 | - | |
| ECOVACS | DEEBOT X5 PRO ULTRA | 0 ~ 1.17.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-11147 | 7.6 HIGH | ECOVACS lawnmowers and vacuums deterministic root password |
| CVE-2024-52331 | 7.5 HIGH | ECOVACS lawnmowers and vacuums deterministic firmware encryption key |
| CVE-2024-52330 | 7.4 HIGH | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates |
| CVE-2024-52329 | 7.4 HIGH | ECOVACS HOME mobile app plugins do not properly validate TLS certificates |
| CVE-2024-52327 | 6.5 MEDIUM | ECOVACS lawnmower and vacuum cloud service live video PIN bypass |
| CVE-2024-12078 | 6.3 MEDIUM | ECOVACS lawnmowers and vacuums static BLE GATT encryption key |
| CVE-2024-12079 | 3.3 LOW | ECOVACS lawnmowers cleartext storage of anti-theft PIN |
| CVE-2024-52328 | 2.3 LOW | ECOVACS lawnmowers and vacuums insecurely store audio warning files |
No comments yet