CVE-2024-52325

Severity CVSS v4.0:
MEDIUM
Type:
CWE-77 Command Injection
Publication date:
23/01/2025
Last modified:
23/09/2025

Description

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ecovacs:goat_g1-2000_firmware:*:*:*:*:*:*:*:* 1.36.187 (excluding)
cpe:2.3:h:ecovacs:goat_g1-2000:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1_firmware:*:*:*:*:*:*:*:* 1.36.187 (excluding)
cpe:2.3:h:ecovacs:goat_g1:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1-800_firmware:*:*:*:*:*:*:*:* 1.36.187 (excluding)
cpe:2.3:h:ecovacs:goat_g1-800:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:gx-600_firmware:*:*:*:*:*:*:*:* 1.2.120 (excluding)
cpe:2.3:h:ecovacs:gx-600:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:* 1.76.6 (excluding)
cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:* 1.81.10 (excluding)
cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:* 1.49.0 (excluding)
cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:* 1.70.0 (excluding)