Authenticated Bypass Vulnerability in ECOVACS Robot Lawn Care Products
CVE-2024-52327
6MEDIUM
What is CVE-2024-52327?
A vulnerability has been identified in the cloud service utilized by ECOVACS robot lawnmowers and vacuums, which permits authenticated attackers to circumvent the necessary PIN entry. This flaw allows unauthorized access to the live video feed of the devices, potentially exposing sensitive visual information to untrusted parties. Users of ECOVACS products should be aware of this risk and take precautionary measures to secure their devices.
Affected Version(s)
cloud service 0 < 2024-12-17
ECOVACS HOME 0 < 3.0.2
cloud service 2024-12-17
