7.5

CVE-2025-30199

Medienbericht

ECOVACS Vacuum and Base Station accept unsigned firmware

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EcovacsDeebot X1s Pro Firmware Version < 2.5.38
   EcovacsDeebot X1s Pro Version-
EcovacsDeebot X1 Pro Omni Firmware Version < 2.5.38
   EcovacsDeebot X1 Pro Omni Version-
EcovacsDeebot X1 Omni Firmware Version < 2.4.45
   EcovacsDeebot X1 Omni Version-
EcovacsDeebot X1s Pro Firmware Version < 2.4.45
   EcovacsDeebot X1s Pro Version-
EcovacsDeebot X1 Turbo Firmware Version < 2.5.38
   EcovacsDeebot X1 Turbo Version-
EcovacsDeebot X1s Pro Firmware Version < 2.4.45
   EcovacsDeebot X1s Pro Version-
EcovacsDeebot T10 Firmware Version < 1.11.0
   EcovacsDeebot T10 Version-
EcovacsDeebot T10 Omni Firmware Version < 1.11.0
   EcovacsDeebot T10 Omni Version-
EcovacsDeebot T10 Plus Firmware Version < 1.11.0
   EcovacsDeebot T10 Plus Version-
EcovacsDeebot T10 Turbo Firmware Version < 1.11.0
   EcovacsDeebot T10 Turbo Version-
EcovacsDeebot T20 Omni Firmware Version < 1.25.0
   EcovacsDeebot T20 Omni Version-
EcovacsDeebot T20 Pro Plus Firmware Version < 1.25.0
   EcovacsDeebot T20 Pro Plus Version-
EcovacsDeebot T20 Pro Firmware Version < 1.25.0
   EcovacsDeebot T20 Pro Version-
EcovacsDeebot T30 Omni Firmware Version < 1.100.0
   EcovacsDeebot T30 Omni Version-
EcovacsDeebot T30s Firmware Version < 1.100.0
   EcovacsDeebot T30s Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.182
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
9119a7d8-5eab-497f-8521-727c672e3725 7.5 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9119a7d8-5eab-497f-8521-727c672e3725 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-494 Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2025 13:51
https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-19
Third Party Advisory
US Government Resource
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-135-19.json
Third Party Advisory
https://www.cve.org/CVERecord?id=CVE-2025-30199
Third Party Advisory