Home

Description

Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.

PUBLISHED Reserved 2025-03-17 | Published 2025-05-23 | Updated 2025-09-30 | Assigner TML




MEDIUM: 4.7CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H

Problem types

CWE-798 Use of Hard-coded Credentials

Product status

Default status
unaffected

3.3.0 (iOS, Android)
affected

References

www.themissinglink.com.au/security-advisories/cve-2025-2394

www.ecovacs.com/global/userhelp/dsa20250507001

cve.org (CVE-2025-2394)

nvd.nist.gov (CVE-2025-2394)

Download JSON