CVE-2025-30199

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
05/09/2025
Last modified:
23/09/2025

Description

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:* 2.5.38 (excluding)
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:* 2.5.38 (excluding)
cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:* 2.4.45 (excluding)
cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:* 2.4.45 (excluding)
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:* 2.5.38 (excluding)
cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:* 2.4.45 (excluding)
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:* 1.11.0 (excluding)
cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:* 1.11.0 (excluding)