Product
ecovacs deebot x1 turbo firmware
4 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-30200
CVE-2025-30199
CVE-2025-30198
CVE-2024-52330
< 2.5.38
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which c
< 2.5.38
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station
< 2.5.38
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easi
< 2.4.41
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traff