Use of Hard-coded Cryptographic Key in ECOVACS products - CVE-2025-30198
Published: May 23, 2025
Vulnerability identifier: #VU109663
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30198
CWE-ID: CWE-321
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to use of hard-coded WPA2-PSK cryptographic key. A remote attacker on the local network can derive the key from the device serial number.
Affected software
T10 Series
T20 Series
T30 Series
X1 OMNI
X1 TURBO
X1S PRO
X1 PRO OMNI
T20 Series
T30 Series
X1 OMNI
X1 TURBO
X1S PRO
X1 PRO OMNI
How to mitigate CVE-2025-30198
Install updates from vendor's website.
T10 Series - update to 1.11.0
T20 Series - update to 1.25.0
T30 Series - update to 1.100.0
X1 OMNI - update to 2.4.45
X1 TURBO - update to 2.4.45
X1S PRO - update to 2.5.38
X1 PRO OMNI - update to 2.5.38
T20 Series - update to 1.25.0
T30 Series - update to 1.100.0
X1 OMNI - update to 2.4.45
X1 TURBO - update to 2.4.45
X1S PRO - update to 2.5.38
X1 PRO OMNI - update to 2.5.38