← back
CVE-2024-52327mediumCWE-603CWE-807

ECOVACS lawnmower and vacuum cloud service live video PIN bypass

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
In short

ECOVACS robot lawnmowers and vacuums have a security flaw that lets someone who is already logged into the cloud service skip the PIN protection and watch the live video feed. This is a problem because the PIN was meant to be an extra security layer to keep your home's video private.

Technical detail

Authenticated attackers can bypass PIN verification (CWE-603: Use of Hard-Coded Password) on the ECOVACS cloud service to access live video feeds from connected devices. The vulnerability requires prior authentication to the cloud account (CWE-807: Reliance on Hard-Coded IP Address) but circumvents an additional authorization control, potentially exposing unauthorized surveillance capabilities.

Summary generated and translated by AI from the official description.
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N