CVE-2024-52325

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ecovacs:goat_g1-2000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1-2000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ecovacs:goat_g1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ecovacs:goat_g1-800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1-800:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ecovacs:gx-600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:gx-600:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t30_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30_omni:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30s:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-23 16:15

Updated : 2025-09-23 17:35


NVD link : CVE-2024-52325

Mitre link : CVE-2024-52325

CVE.ORG link : CVE-2024-52325


JSON object : View

Products Affected

ecovacs

  • deebot_t30s_firmware
  • deebot_t30_omni
  • goat_g1_firmware
  • deebot_t30s
  • deebot_x5_pro_plus_firmware
  • goat_g1
  • deebot_x5_pro_ultra_firmware
  • goat_g1-800_firmware
  • goat_g1-800
  • deebot_x2_omni_firmware
  • deebot_x5_pro_ultra
  • deebot_x2s_firmware
  • deebot_t30_omni_firmware
  • deebot_x2_omni
  • deebot_x2s
  • goat_g1-2000_firmware
  • deebot_x2_combo
  • deebot_x5_pro_plus
  • deebot_x5_pro_firmware
  • goat_g1-2000
  • deebot_x2_combo_firmware
  • deebot_x5_pro
  • gx-600_firmware
  • gx-600
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')