Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hqv-x23m-4c88

Опубликовано: 05 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.5
CVSS3: 7.2

Описание

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

EPSS

Процентиль: 6%
0.00024
Низкий

7.5 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 7.2
nvd
5 месяцев назад

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

EPSS

Процентиль: 6%
0.00024
Низкий

7.5 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-494