CVE-2024-52325

CRITICALCVSS 9.6/10EPSS 2.98%

Last modified

CVE-2024-52325 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.. EPSS estimates a 2.98% chance of exploitation in the next 30 days.

Description

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
EcovacsGoat G1-2000 Firmware< 1.36.187
EcovacsGoat G1 Firmware< 1.36.187
EcovacsGoat G1-800 Firmware< 1.36.187
EcovacsGx-600 Firmware< 1.2.120
EcovacsDeebot X2 Omni Firmware< 1.76.6
EcovacsDeebot X2 Combo Firmware< 1.81.10
EcovacsDeebot X2s Firmware< 1.49.0
EcovacsDeebot X5 Pro Firmware< 1.70.0
EcovacsDeebot X5 Pro Plus Firmware< 1.38.0
EcovacsDeebot X5 Pro Ultra Firmware< 1.17.0
EcovacsDeebot T30 Omni Firmware< 1.93.0
EcovacsDeebot T30s Firmware< 1.95.0

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-52325?
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
How severe is CVE-2024-52325?
CVE-2024-52325 has a CVSS score of 9.6/10 (CRITICAL severity). The EPSS model estimates a 2.98% probability of exploitation in the next 30 days.
How do I fix CVE-2024-52325?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-52325?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST