ECOVACS Robots and Lawn Mowers Insufficient PIN Validation Vulnerability for Live Video Feed Access

Vulnerability

A vulnerability exists in the cloud service for ECOVACS robot lawnmowers and vacuums, allowing authenticated attackers to bypass the PIN requirement for accessing the live video feed. This issue arises from inadequate validation of the PIN, enabling unauthorized access to the video stream.

Impact

Exploitation of this vulnerability allows for unauthorized access to the live video feed from the affected ECOVACS devices.

Remediation

Users can update to the latest version of the ECOVACS HOME app, version 3.0.2 or later, which addresses this vulnerability. The app can be downloaded from the Apple App Store or Google Play Store, or manually installed from the ECOVACS official website or app download center.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.