Description
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
Problem types
CWE-321 Use of Hard-coded Cryptographic Key
CWE-798 Use of Hard-coded Credentials
Product status
*
*
*
*
Credits
Dennis Giese, undefined
Braelynn Luedtke, undefined
Chris Anderson, undefined
References
www.cisa.gov/news-events/ics-advisories/icsa-25-135-19 (url)
github.com/...p/csaf_files/OT/white/2025/icsa-25-135-19.json (url)
www.cve.org/CVERecord?id=CVE-2025-30200 (url)