📦 Deebot T10 Firmware

by Ecovacs

🔍 What is Deebot T10 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-30199

HIGH CVSS 7.2 Sep 5, 2025

ECOVACS vacuum robot base stations lack firmware update validation, allowing attackers to send malicious over-the-air updates via the insecure connection between robot and base station. This affects E...

CVE-2024-52330

HIGH CVSS 7.4 Jan 23, 2025

ECOVACS robotic lawnmowers and vacuums fail to properly validate TLS certificates, allowing unauthenticated attackers to intercept and manipulate TLS traffic. This could enable firmware update tamperi...

CVE-2024-52331

HIGH CVSS 7.5 Jan 23, 2025

ECOVACS robot lawnmowers and vacuums use a predictable symmetric key for firmware decryption, allowing attackers to create and install malicious firmware. This affects all ECOVACS robot models that re...

CVE-2024-11147

HIGH CVSS 7.6 Jan 23, 2025

ECOVACS robot lawnmowers and vacuums have a predictable root password generated from model and serial number, allowing attackers with shell access to gain full system control. This affects all ECOVACS...

CVE-2025-30198

MEDIUM CVSS 6.3 Sep 5, 2025

ECOVACS robot vacuums and base stations use a predictable WPA2-PSK that can be easily derived, allowing attackers to join the local Wi-Fi network. This affects all ECOVACS robot vacuum models and base...

CVE-2024-12078

MEDIUM CVSS 6.3 Jan 23, 2025

ECOVACS robot lawn mowers and vacuums use a static, shared secret key to encrypt Bluetooth Low Energy (BLE) GATT messages, allowing unauthenticated attackers within BLE range to control any robot usin...