CVE-2025-30198
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-05

Last updated on: 2025-09-23

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-05
Last Modified
2025-09-23
Generated
2026-05-07
AI Q&A
2025-09-05
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 30 associated CPEs
Vendor Product Version / Range
ecovacs deebot_x1s_pro_firmware to 2.5.38 (exc)
ecovacs deebot_x1s_pro *
ecovacs deebot_x1_pro_omni_firmware to 2.5.38 (exc)
ecovacs deebot_x1_pro_omni *
ecovacs deebot_x1_omni_firmware to 2.4.45 (exc)
ecovacs deebot_x1_omni *
ecovacs deebot_x1s_pro_firmware to 2.4.45 (exc)
ecovacs deebot_x1s_pro *
ecovacs deebot_x1_turbo_firmware to 2.5.38 (exc)
ecovacs deebot_x1_turbo *
ecovacs deebot_x1s_pro_firmware to 2.4.45 (exc)
ecovacs deebot_x1s_pro *
ecovacs deebot_t10_firmware to 1.11.0 (exc)
ecovacs deebot_t10 *
ecovacs deebot_t10_omni_firmware to 1.11.0 (exc)
ecovacs deebot_t10_omni *
ecovacs deebot_t10_plus_firmware to 1.11.0 (exc)
ecovacs deebot_t10_plus *
ecovacs deebot_t10_turbo_firmware to 1.11.0 (exc)
ecovacs deebot_t10_turbo *
ecovacs deebot_t20_omni_firmware to 1.25.0 (exc)
ecovacs deebot_t20_omni *
ecovacs deebot_t20_pro_plus_firmware to 1.25.0 (exc)
ecovacs deebot_t20_pro_plus *
ecovacs deebot_t20_pro_firmware to 1.25.0 (exc)
ecovacs deebot_t20_pro *
ecovacs deebot_t30_omni_firmware to 1.100.0 (exc)
ecovacs deebot_t30_omni *
ecovacs deebot_t30s_firmware to 1.100.0 (exc)
ecovacs deebot_t30s *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves ECOVACS robot vacuums and their base stations communicating over a Wi-Fi network secured with a deterministic WPA2-PSK (pre-shared key) that is insecure and can be easily derived by an attacker.


How can this vulnerability impact me? :

An attacker who derives the WPA2-PSK can potentially intercept or manipulate communications between the robot vacuum and its base station, leading to unauthorized access or control of the device.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart