CVE-2024-12078

Publication date

2025-01-23 16:38:48

Family

cisa-cg

State

PUBLISHED

Description

ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.