Download of code without integrity check in ECOVACS products - CVE-2025-30199

 

Download of code without integrity check in ECOVACS products - CVE-2025-30199

Published: May 23, 2025


Vulnerability identifier: #VU109664
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30199
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system

The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote administor can send malicious over-the-air updates to base station via insecure connection between robot and base station.


Affected software

T10 Series
T20 Series
T30 Series
X1 OMNI
X1 TURBO
X1S PRO
X1 PRO OMNI

How to mitigate CVE-2025-30199

Install updates from vendor's website.

T10 Series - update to 1.11.0
T20 Series - update to 1.25.0
T30 Series - update to 1.100.0
X1 OMNI - update to 2.4.45
X1 TURBO - update to 2.4.45
X1S PRO - update to 2.5.38
X1 PRO OMNI - update to 2.5.38

External References

Related Security Bulletins