CVE-2024-52325
9.6
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.6), but no sign of active exploitation.
Description
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Scoring
| CVSS | 9.6 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 3.04% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-01-23 |
| Last modified | 2026-06-17 |
Affected (24)
| Vendor | Product |
|---|---|
| ecovacs | deebot t30 omni |
| ecovacs | deebot t30 omni firmware |
| ecovacs | deebot t30s |
| ecovacs | deebot t30s firmware |
| ecovacs | deebot x2 combo |
| ecovacs | deebot x2 combo firmware |
| ecovacs | deebot x2 omni |
| ecovacs | deebot x2 omni firmware |
| ecovacs | deebot x2s |
| ecovacs | deebot x2s firmware |
| ecovacs | deebot x5 pro |
| ecovacs | deebot x5 pro firmware |
| ecovacs | deebot x5 pro plus |
| ecovacs | deebot x5 pro plus firmware |
| ecovacs | deebot x5 pro ultra |
| ecovacs | deebot x5 pro ultra firmware |
| ecovacs | goat g1 |
| ecovacs | goat g1 firmware |
| ecovacs | goat g1-2000 |
| ecovacs | goat g1-2000 firmware |
| ecovacs | goat g1-800 |
| ecovacs | goat g1-800 firmware |
| ecovacs | gx-600 |
| ecovacs | gx-600 firmware |
References
→ the Explorer · watch your stack · NVD