CVE-2024-52327

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/01/2025
Last modified:
23/09/2025

Description

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ecovacs:home:*:*:*:*:*:android:*:* 3.0.2 (excluding)
cpe:2.3:a:ecovacs:home:*:*:*:*:*:iphone_os:*:* 3.0.2 (excluding)