Home
MEDIUM: 4.7 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:HDefault status
unaffected
3.3.0 (iOS, Android)
affected
Description
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
3.3.0 (iOS, Android)
References
www.themissinglink.com.au/security-advisories/cve-2025-2394
www.ecovacs.com/global/userhelp/dsa20250507001