« Volver al listado

Ecovacs

Ecovacs Deebot X1S PRO Firmware: vulnerabilidades y CVE

Ecovacs Deebot X1S PRO Firmware tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-30200Baja (2.3)0.14%—5 sept 2025
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
CVE-2025-30199Alta (7.5)0.29%—5 sept 2025
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
CVE-2025-30198Baja (2.3)0.22%—5 sept 2025
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
CVE-2024-52330Crítica (9.5)0.35%—23 ene 2025
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1195 Supply Chain Compromise1
  2. T1195.002 Compromise Software Supply Chain1
  3. T1557 Adversary-in-the-Middle1
  4. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Ecovacs