ECOVACS Robots and Lawn Mowers Insufficient PIN Validation Vulnerability for Live Video Feed Access
Vulnerability
A vulnerability exists in the cloud service for ECOVACS robot lawnmowers and vacuums, allowing authenticated attackers to bypass the PIN requirement for accessing the live video feed. This issue arises from inadequate validation of the PIN, enabling unauthorized access to the video stream.
Impact
Exploitation of this vulnerability allows for unauthorized access to the live video feed from the affected ECOVACS devices.
Remediation
Users can update to the latest version of the ECOVACS HOME app, version 3.0.2 or later, which addresses this vulnerability. The app can be downloaded from the Apple App Store or Google Play Store, or manually installed from the ECOVACS official website or app download center.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
