CISA advisory: Ecovacs Deebot base stations accept unvalidated firmware updates, deterministic WiFi key
S1 · ~May 2025 · Ecovacs
Record
| Company | Ecovacs |
| Industry | Consumer robotics |
| Type(s) | cyber |
| Date | ~May 2025 (month precision) |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | (near-miss / disclosed vulnerability) |
| Scale | Deebot Goat G1, Deebot 900/N8/T8 and related models |
| Confidence | high |
| Verified flag | Cited source on file; not independently re-verified |
Summary
CISA published ICS advisory ICSA-25-135-19 describing vulnerabilities in Ecovacs Deebot vacuums and base stations, including base stations that do not validate firmware updates (allowing malicious OTA pushes) and a deterministic WPA2-PSK derivable from the device serial number. Ecovacs released patches; no known public exploitation was reported.
Primary source
Publisher: CISA · Retrieved: 2026-09-16
Supporting source rows (1)
| Date | Supporting source row | Publisher | Link |
|---|---|---|---|
| ~May 2025 | CISA advisory: Ecovacs Deebot base stations accept unvalidated firmware updates, deterministic WiFi key | CISA | CISA |
Ecovacs other incidents timeline
Consumer robotics context
cyber context
Ecovacs industry position
Related incidents
Other Ecovacs entries
- ~Aug 2024 - Researchers demonstrate Bluetooth/PIN flaw letting attackers hijack Ecovacs Deebot cameras and mics
- ~May 2024 - Hacked Ecovacs Deebot X2 vacuums shout racial slurs, chase pet in multiple US cities
Report a correction
Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs