CVE-2024-52330

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ecovacs:mate_x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:mate_x:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_plus:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1s_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro_plus:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1e_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1e_omni:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_pro:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-23 17:15

Updated : 2025-09-23 17:48


NVD link : CVE-2024-52330

Mitre link : CVE-2024-52330

CVE.ORG link : CVE-2024-52330


JSON object : View

Products Affected

ecovacs

  • deebot_t10
  • deebot_x1s_pro_plus
  • deebot_x2_pro_firmware
  • deebot_x1_firmware
  • deebot_x5_pro_plus_firmware
  • deebot_t10_turbo
  • deebot_x5_pro_ultra_firmware
  • deebot_x2_pro
  • deebot_x1_pro_omni
  • deebot_x1s_pro
  • deebot_t10_plus
  • deebot_x2_omni_firmware
  • deebot_x1_omni_firmware
  • deebot_x5_pro_ultra
  • deebot_x1e_omni
  • deebot_x2s_firmware
  • deebot_t10_omni_firmware
  • deebot_x2_omni
  • deebot_x1s_pro_firmware
  • deebot_t10_omni
  • deebot_x1_plus
  • mate_x_firmware
  • deebot_x2s
  • deebot_x1_plus_firmware
  • deebot_t10_plus_firmware
  • deebot_x2_combo
  • deebot_x5_pro_plus
  • deebot_x5_pro_firmware
  • deebot_x1_turbo
  • deebot_x2_combo_firmware
  • deebot_x5_pro
  • deebot_x1e_omni_firmware
  • deebot_x1s_pro_plus_firmware
  • mate_x
  • deebot_x1_pro_omni_firmware
  • deebot_t10_firmware
  • deebot_x1
  • deebot_x1_turbo_firmware
  • deebot_t10_turbo_firmware
  • deebot_x1_omni
CWE
CWE-295

Improper Certificate Validation