CVE-2024-52325: Ecovacs Deebot t30 Omni Firmware
Critical severity, CVSS 9.6. EPSS: 3% chance of exploitation in the next 30 days.
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Affected products
- Ecovacs Deebot t30 Omni Firmware: before 1.93.0 (fixed in 1.93.0)
- Ecovacs Deebot t30s Firmware: before 1.95.0 (fixed in 1.95.0)
- Ecovacs Deebot x2 Combo Firmware: before 1.81.10 (fixed in 1.81.10)
- Ecovacs Deebot x2 Omni Firmware: before 1.76.6 (fixed in 1.76.6)
- Ecovacs Deebot x2s Firmware: before 1.49.0 (fixed in 1.49.0)
- Ecovacs Deebot x5 Pro Firmware: before 1.70.0 (fixed in 1.70.0)
- Ecovacs Deebot x5 Pro Plus Firmware: before 1.38.0 (fixed in 1.38.0)
- Ecovacs Deebot x5 Pro Ultra Firmware: before 1.17.0 (fixed in 1.17.0)
- Ecovacs Goat g1-2000 Firmware: before 1.36.187 (fixed in 1.36.187)
- Ecovacs Goat g1-800 Firmware: before 1.36.187 (fixed in 1.36.187)
- Ecovacs Goat g1 Firmware: before 1.36.187 (fixed in 1.36.187)
- Ecovacs Gx-600 Firmware: before 1.2.120 (fixed in 1.2.120)
Published 2025-01-23. Last modified 2026-06-17.