peter bassill · operator
$ cve CVE-2024-52325 JSON

CVE-2024-52325

9.6
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.6), but no sign of active exploitation.

Description

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

Scoring

CVSS9.6 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.04% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2025-01-23
Last modified2026-06-17

Affected (24)

VendorProduct
ecovacsdeebot t30 omni
ecovacsdeebot t30 omni firmware
ecovacsdeebot t30s
ecovacsdeebot t30s firmware
ecovacsdeebot x2 combo
ecovacsdeebot x2 combo firmware
ecovacsdeebot x2 omni
ecovacsdeebot x2 omni firmware
ecovacsdeebot x2s
ecovacsdeebot x2s firmware
ecovacsdeebot x5 pro
ecovacsdeebot x5 pro firmware
ecovacsdeebot x5 pro plus
ecovacsdeebot x5 pro plus firmware
ecovacsdeebot x5 pro ultra
ecovacsdeebot x5 pro ultra firmware
ecovacsgoat g1
ecovacsgoat g1 firmware
ecovacsgoat g1-2000
ecovacsgoat g1-2000 firmware
ecovacsgoat g1-800
ecovacsgoat g1-800 firmware
ecovacsgx-600
ecovacsgx-600 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD