ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot. | |
Title | ECOVACS lawnmowers and vacuums deterministic firmware encryption key | |
Weaknesses | CWE-1391 CWE-494 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-02-12T20:41:28.822Z
Reserved: 2024-11-08T01:06:02.405Z
Link: CVE-2024-52331

Updated: 2025-02-12T20:35:29.355Z

Status : Received
Published: 2025-01-23T17:15:14.563
Modified: 2025-01-23T17:15:14.563
Link: CVE-2024-52331

No data.