📦 Goat G1 Firmware

by Ecovacs

🔍 What is Goat G1 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-52325

CRITICAL CVSS 9.6 Jan 23, 2025

ECOVACS robot lawnmowers and vacuums are vulnerable to unauthenticated command injection via Bluetooth Low Energy (BLE) connections. Attackers within BLE range can execute arbitrary commands on affect...

CVE-2024-52331

HIGH CVSS 7.5 Jan 23, 2025

ECOVACS robot lawnmowers and vacuums use a predictable symmetric key for firmware decryption, allowing attackers to create and install malicious firmware. This affects all ECOVACS robot models that re...

CVE-2024-11147

HIGH CVSS 7.6 Jan 23, 2025

ECOVACS robot lawnmowers and vacuums have a predictable root password generated from model and serial number, allowing attackers with shell access to gain full system control. This affects all ECOVACS...

CVE-2024-12078

MEDIUM CVSS 6.3 Jan 23, 2025

ECOVACS robot lawn mowers and vacuums use a static, shared secret key to encrypt Bluetooth Low Energy (BLE) GATT messages, allowing unauthenticated attackers within BLE range to control any robot usin...