Vulnerabilities (CVE)

Filtered by vendor Ecovacs Subscribe
Filtered by product Home
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-52327 1 Ecovacs 1 Home 2025-09-23 N/A 6.5 MEDIUM
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
CVE-2024-52329 1 Ecovacs 1 Home 2025-09-23 N/A 7.4 HIGH
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.