CVE-2024-52328
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
23/01/2025
Last modified:
23/01/2025
Description
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.
Impact
Base Score 4.0
1.80
Severity 4.0
LOW
Base Score 3.x
2.30
Severity 3.x
LOW