Back to Database
Status published
Low
CVE-2025-30198
ECOVACS Vacuum and Base Station Hard-Coded WPA2-PSK
Vulnerability Description
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-30198
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Dennis Giese, undefined
- Braelynn Luedtke, undefined
- Chris Anderson, undefined
References
More from ECOVACS
View All →CVE-2025-30200
ECOVACS Vacuum and Base Station Hard-Coded AES Encryption
Low
2.3
CVE-2025-30199
ECOVACS Vacuum and Base Station accept unsigned firmware
High
7.5
CVE-2024-52331
ECOVACS lawnmowers and vacuums deterministic firmware encryption key
High
7.7
CVE-2024-52330
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates
Critical
9.5
CVE-2024-52329
ECOVACS HOME mobile app plugins do not properly validate TLS certificates
Critical
9.5
Affected Vendor
ECOVACS
View all reports →Affected Software
DEEBOT X1 Series, DEEBOT T20 Series, DEEBOT T10 Series, DEEBOT T30 Series
Vulnerable Versions:
*
Timeline
Official Publish:
September 5th, 2025
Last Modified:
September 8th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
MITRE ATT&CK TTPs
T1552
Unsecured Credentials
Credential Access
T1040
Network Sniffing
Credential Access
T1537
Transfer Data to Cloud Account
Credential Access
T1078
Valid Accounts
Persistence
T1041
Exfiltration Over C2 Channel
Exfiltration
T1021
Remote Services
Lateral Movement
T1190
Exploit Public-Facing Application
Initial Access
T1098
Account Manipulation
Privilege Escalation