#VU109665 Use of Hard-coded Cryptographic Key in ECOVACS products - CVE-2025-30200
Published: May 23, 2025
Vulnerability identifier: #VU109665
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-30200
CWE-ID: CWE-321
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
X1S PRO
X1 PRO OMNI
X1 OMNI
X1 TURBO
T10 Series
T20 Series
T30 Series
X1S PRO
X1 PRO OMNI
X1 OMNI
X1 TURBO
T10 Series
T20 Series
T30 Series
Software vendor:
ECOVACS
ECOVACS
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to use of hard-coded AES cryptographic key. A remote attacker on the local network can derive the key from the device serial number.
Remediation
Install updates from vendor's website.