CVE-2025-30198 Details
Description
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
A vulnerability exists in ECOVACS robot vacuums and base stations due to the use of a hard-coded, deterministic WPA2-PSK encryption key for Wi-Fi communication. This key can be easily derived from the device's serial number, leading to potential unauthorized access. Additionally, the base stations do not validate firmware updates, allowing malicious over-the-air updates to be sent via the insecure connection between the robot and the base station.
ECOVACS has released software updates for all affected devices. Users can perform the system update to address this vulnerability. For more information, see the ECOVACS security advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 8, 2025CISA-ADP
Assessed Sep 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-135-19.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-19 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-30198 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
| CWE-321 | Use of Hard-coded Cryptographic Key | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-798 | Use of Hard-coded Credentials | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| ecovacs deebot x1s pro firmware | < 2.5.38 < 2.4.45 |
CPE
Remediation
| |
| ecovacs deebot x1s pro | All versions |
CPE
Remediation
| |
| ecovacs deebot x1 pro omni firmware | < 2.5.38 |
CPE
Remediation
| |
| ecovacs deebot x1 pro omni | All versions |
CPE
Remediation
| |
| ecovacs deebot x1 omni firmware | < 2.4.45 |
CPE
Remediation
| |
| ecovacs deebot x1 omni | All versions |
CPE
Remediation
| |
| ecovacs deebot x1 turbo firmware | < 2.5.38 |
CPE
Remediation
| |
| ecovacs deebot x1 turbo | All versions |
CPE
Remediation
| |
| ecovacs deebot t10 firmware | < 1.11.0 |
CPE
Remediation
| |
| ecovacs deebot t10 | All versions |
CPE
Remediation
| |
| ecovacs deebot t10 omni firmware | < 1.11.0 |
CPE
Remediation
| |
| ecovacs deebot t10 omni | All versions |
CPE
Remediation
| |
| ecovacs deebot t10 plus firmware | < 1.11.0 |
CPE
Remediation
| |
| ecovacs deebot t10 plus | All versions |
CPE
Remediation
| |
| ecovacs deebot t10 turbo firmware | < 1.11.0 |
CPE
Remediation
| |
| ecovacs deebot t10 turbo | All versions |
CPE
Remediation
| |
| ecovacs deebot t20 omni firmware | < 1.25.0 |
CPE
Remediation
| |
| ecovacs deebot t20 omni | All versions |
CPE
Remediation
| |
| ecovacs deebot t20 pro plus firmware | < 1.25.0 |
CPE
Remediation
| |
| ecovacs deebot t20 pro plus | All versions |
CPE
Remediation
| |
| ecovacs deebot t20 pro firmware | < 1.25.0 |
CPE
Remediation
| |
| ecovacs deebot t20 pro | All versions |
CPE
Remediation
| |
| ecovacs deebot t30 omni firmware | < 1.100.0 |
CPE
Remediation
| |
| ecovacs deebot t30 omni | All versions |
CPE
Remediation
| |
| ecovacs deebot t30s firmware | < 1.100.0 |
CPE
Remediation
| |
| ecovacs deebot t30s | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | Initial Analysis | [email protected] |
| Sep 5, 2025 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |