Description
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
Problem types
CWE-494 Download of Code Without Integrity Check
Product status
*
*
*
*
Credits
Dennis Giese, undefined
Braelynn Luedtke, undefined
Chris Anderson, undefined
References
www.cisa.gov/news-events/ics-advisories/icsa-25-135-19 (url)
github.com/...p/csaf_files/OT/white/2025/icsa-25-135-19.json (url)
www.cve.org/CVERecord?id=CVE-2025-30199 (url)