CVE Vulnerabilities

CVE-2024-52327

Use of Client-Side Authentication

Published: Jan 23, 2025 | Modified: Sep 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

Weakness

A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

Affected Software

NameVendorStart VersionEnd Version
HomeEcovacs*3.0.2 (excluding)

Potential Mitigations

References