ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key. | |
Title | ECOVACS lawnmowers and vacuums static BLE GATT encryption key | |
Weaknesses | CWE-321 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-02-12T17:11:14.933Z
Reserved: 2024-12-02T23:55:12.974Z
Link: CVE-2024-12078

Updated: 2025-02-12T17:11:05.672Z

Status : Received
Published: 2025-01-23T17:15:13.020
Modified: 2025-01-23T17:15:13.020
Link: CVE-2024-12078

No data.