CVE-2024-12078
MEDIUMDescription
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
Is your site exposed to CVE-2024-12078?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ecovacs | deebot_n10_firmware |
| ecovacs | deebot_n10 |
| ecovacs | deebot_t10_firmware |
| ecovacs | deebot_t10 |
| ecovacs | deebot_x1_firmware |
| ecovacs | deebot_x1 |
| ecovacs | deebot_t20_firmware |
| ecovacs | deebot_t20 |
| ecovacs | deebot_x2_firmware |
| ecovacs | deebot_x2 |
| ecovacs | goat_g1_firmware |
| ecovacs | goat_g1 |
| ecovacs | airbot_z1_firmware |
| ecovacs | airbot_z1 |
| ecovacs | airbot_ava_firmware |
| ecovacs | airbot_ava |
| ecovacs | airbot_andy_firmware |
| ecovacs | airbot_andy |
| ecovacs | deebot_900_firmware |
| ecovacs | deebot_900 |
| ecovacs | deebot_n8_firmware |
| ecovacs | deebot_n8 |
| ecovacs | deebot_t8_firmware |
| ecovacs | deebot_t8 |
| ecovacs | deebot_n9_firmware |
| ecovacs | deebot_n9 |
| ecovacs | deebot_t9_firmware |
| ecovacs | deebot_t9 |
References
Frequently Asked Questions
What is CVE-2024-12078? +
How severe is CVE-2024-12078? +
What products are affected by CVE-2024-12078? +
How do I check if I'm vulnerable to CVE-2024-12078? +
Related Vulnerabilities
The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to …
The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to …
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructure.Security.dll component. An attacker with access to …
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the …
This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An …
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key …