Ecovacs manufactures a range of robotic vacuum and floor-cleaning devices marketed under the Deebot and Goat product lines, presenting a consumer IoT attack surface spanning firmware and companion applications. Its vulnerability disclosures recur through configuration and credential-management weakness classes—hard-coded credentials, hard-coded cryptographic keys, cleartext storage of sensitive information, and improper certificate validation—that are characteristic of connected appliances with limited update discipline and embedded authentication. A meaningful share of the vendor's vulnerabilities reach serious severity; live exploitation activity and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecovacs over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52325CRITICAL ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection. | Jan 23, 2025 | 9.6 | 30 | NO | NO |
CVE-2025-30199HIGH ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base st | Sep 5, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-30200MEDIUM ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived. | Sep 5, 2025 | 6.3 | 21 | NO | NO |
CVE-2025-30198MEDIUM ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived. | Sep 5, 2025 | 6.3 | 21 | NO | NO |
CVE-2024-52331HIGH ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully | Jan 23, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-52330HIGH ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates. | Jan 23, 2025 | 7.4 | 21 | NO | NO |
CVE-2024-52329HIGH ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication | Jan 23, 2025 | 7.4 | 21 | NO | NO |
CVE-2024-11147HIGH ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root. | Jan 23, 2025 | 7.6 | 21 | NO | NO |
CVE-2024-52327MEDIUM The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed. | Jan 23, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-12078MEDIUM ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the sam | Jan 23, 2025 | 6.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecovacs.
Media articles that mention a CVE ID that affects a product developed by Ecovacs — matched by CVE ID, not by vendor name.