Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · ecovacs

ecovacs

· 1 Critical

Total CVEs

12

Critical

1

Products

81

Search All CVEs →

12

Products (81)

deebot t109 CVEsdeebot t10 firmware9 CVEsgoat g1 firmware6 CVEsgoat g16 CVEsdeebot x16 CVEsdeebot x1 firmware6 CVEsdeebot t8 firmware5 CVEsdeebot t95 CVEsdeebot t9 firmware5 CVEsdeebot n8 firmware5 CVEsdeebot n95 CVEsdeebot n9 firmware5 CVEsairbot andy firmware5 CVEsairbot ava5 CVEsairbot ava firmware5 CVEsairbot z15 CVEsairbot z1 firmware5 CVEsdeebot 9005 CVEsdeebot t205 CVEsdeebot t20 firmware5 CVEsdeebot x2 firmware5 CVEsairbot andy5 CVEsdeebot x25 CVEsdeebot 900 firmware5 CVEsdeebot n105 CVEsdeebot n10 firmware5 CVEsdeebot n85 CVEsdeebot t85 CVEsdeebot x1s pro4 CVEsdeebot t10 omni4 CVEsdeebot t10 omni firmware4 CVEsdeebot t10 plus4 CVEsdeebot t10 plus firmware4 CVEsdeebot t10 turbo4 CVEsdeebot t10 turbo firmware4 CVEsdeebot t30 omni4 CVEsdeebot t30 omni firmware4 CVEsdeebot t30s4 CVEsdeebot t30s firmware4 CVEsdeebot x1 omni4 CVEsdeebot x1 omni firmware4 CVEsdeebot x1 pro omni4 CVEsdeebot x1 pro omni firmware4 CVEsdeebot x1 turbo4 CVEsdeebot x1 turbo firmware4 CVEsdeebot x1s pro firmware4 CVEsdeebot t20 pro firmware3 CVEsdeebot t20 omni3 CVEsdeebot t20 pro plus firmware3 CVEsdeebot t20 omni firmware3 CVEsdeebot t20 pro plus3 CVEsdeebot t20 pro3 CVEshome2 CVEsdeebot x2 combo2 CVEsdeebot x2 combo firmware2 CVEsdeebot x2 omni2 CVEsdeebot x2 omni firmware2 CVEsdeebot x2s2 CVEsdeebot x2s firmware2 CVEsdeebot x5 pro2 CVEsdeebot x5 pro firmware2 CVEsdeebot x5 pro plus2 CVEsdeebot x5 pro plus firmware2 CVEsdeebot x5 pro ultra2 CVEsdeebot x5 pro ultra firmware2 CVEsmate x1 CVEsdeebot x1 plus1 CVEsdeebot x1 plus firmware1 CVEsgx-6001 CVEsdeebot x1s pro plus firmware1 CVEsdeebot x1s pro plus1 CVEsgx-600 firmware1 CVEsdeebot x1e omni firmware1 CVEsmate x firmware1 CVEsgoat g1-20001 CVEsgoat g1-2000 firmware1 CVEsdeebot x2 pro1 CVEsdeebot x2 pro firmware1 CVEsgoat g1-8001 CVEsdeebot x1e omni1 CVEsgoat g1-800 firmware1 CVEs

Recent Vulnerabilities

View all 12
CVE-2025-30200MEDIUM 6.3

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.

CVE-2025-30199HIGH 7.2

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.

CVE-2025-30198MEDIUM 6.3

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

CVE-2024-52331HIGH 7.5

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.

CVE-2024-52330HIGH 7.4

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

CVE-2024-52329HIGH 7.4

ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.

CVE-2024-52328LOW 2.3

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.

CVE-2024-52327MEDIUM 6.5

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

CVE-2024-12079LOW 3.3

ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.

CVE-2024-12078MEDIUM 6.3

ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.

CVE-2024-11147HIGH 7.6

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.

CVE-2024-52325CRITICAL 9.6

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.