ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
| Software | From | Fixed in |
|---|---|---|
| ecovacs / deebot_x1s_pro_firmware | - | 2.5.38 |
| ecovacs / deebot_x1_pro_omni_firmware | - | 2.5.38 |
| ecovacs / deebot_x1_omni_firmware | - | 2.4.45 |
| ecovacs / deebot_x1s_pro_firmware | - | 2.4.45 |
| ecovacs / deebot_x1_turbo_firmware | - | 2.5.38 |
| ecovacs / deebot_t10_firmware | - | 1.11.0 |
| ecovacs / deebot_t10_omni_firmware | - | 1.11.0 |
| ecovacs / deebot_t10_plus_firmware | - | 1.11.0 |
| ecovacs / deebot_t10_turbo_firmware | - | 1.11.0 |
| ecovacs / deebot_t20_omni_firmware | - | 1.25.0 |
| ecovacs / deebot_t20_pro_plus_firmware | - | 1.25.0 |
| ecovacs / deebot_t20_pro_firmware | - | 1.25.0 |
| ecovacs / deebot_t30_omni_firmware | - | 1.100.0 |
| ecovacs / deebot_t30s_firmware | - | 1.100.0 |