Cleartext Anti-theft PIN Vulnerability in ECOVACS Robot Lawnmowers
CVE-2024-12079
4.8MEDIUM
What is CVE-2024-12079?
ECOVACS robot lawnmowers are at risk due to their practice of storing anti-theft PINs in cleartext on the device's filesystem. This vulnerability allows attackers who physically access the device to effortlessly read the stored PIN, leading to potential theft and the ability to reset the anti-theft mechanism. Users of ECOVACS lawnmowers should be aware of this security flaw and take appropriate measures to safeguard their devices.
Affected Version(s)
Unspecified robots *
