CVE-2024-52331
HIGHDescription
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
Is your site exposed to CVE-2024-52331?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ecovacs | deebot_900_firmware |
| ecovacs | deebot_900 |
| ecovacs | deebot_n8_firmware |
| ecovacs | deebot_n8 |
| ecovacs | deebot_t8_firmware |
| ecovacs | deebot_t8 |
| ecovacs | deebot_n9_firmware |
| ecovacs | deebot_n9 |
| ecovacs | deebot_t9_firmware |
| ecovacs | deebot_t9 |
| ecovacs | deebot_n10_firmware |
| ecovacs | deebot_n10 |
| ecovacs | deebot_t10_firmware |
| ecovacs | deebot_t10 |
| ecovacs | deebot_x1_firmware |
| ecovacs | deebot_x1 |
| ecovacs | deebot_t20_firmware |
| ecovacs | deebot_t20 |
| ecovacs | deebot_x2_firmware |
| ecovacs | deebot_x2 |
| ecovacs | goat_g1_firmware |
| ecovacs | goat_g1 |
| ecovacs | airbot_z1_firmware |
| ecovacs | airbot_z1 |
| ecovacs | airbot_ava_firmware |
| ecovacs | airbot_ava |
| ecovacs | airbot_andy_firmware |
| ecovacs | airbot_andy |
References
Frequently Asked Questions
What is CVE-2024-52331? +
How severe is CVE-2024-52331? +
What products are affected by CVE-2024-52331? +
How do I check if I'm vulnerable to CVE-2024-52331? +
Related Vulnerabilities
An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in …
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used …
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the …
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to 3.9.2 allows …
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to …
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key …