📦 Deebot X1 Firmware

by Ecovacs

🔍 What is Deebot X1 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-52330

HIGH CVSS 7.4 Jan 23, 2025

ECOVACS robotic lawnmowers and vacuums fail to properly validate TLS certificates, allowing unauthenticated attackers to intercept and manipulate TLS traffic. This could enable firmware update tamperi...

CVE-2024-52331

HIGH CVSS 7.5 Jan 23, 2025

ECOVACS robot lawnmowers and vacuums use a predictable symmetric key for firmware decryption, allowing attackers to create and install malicious firmware. This affects all ECOVACS robot models that re...

CVE-2024-11147

HIGH CVSS 7.6 Jan 23, 2025

ECOVACS robot lawnmowers and vacuums have a predictable root password generated from model and serial number, allowing attackers with shell access to gain full system control. This affects all ECOVACS...

CVE-2024-12078

MEDIUM CVSS 6.3 Jan 23, 2025

ECOVACS robot lawn mowers and vacuums use a static, shared secret key to encrypt Bluetooth Low Energy (BLE) GATT messages, allowing unauthenticated attackers within BLE range to control any robot usin...