Products: Vacuum. Risk band: Elevated RobotRisk index 17.7/100 (incidents/exposure, time-weighted) · 96th percentile of 91 consumer robotics companies.
The record shows three cyber-related entries spanning May 2024 to May 2025: hacked Deebot units producing offensive audio and pursuing pets, a demonstrated Bluetooth/PIN flaw enabling camera hijacking, and a CISA advisory citing unvalidated firmware updates at the base-station level. The entries move from press-reported exploitation incidents to a formal government security advisory, showing escalation from isolated abuse cases to a documented systemic vulnerability. Severity is low on each entry (1-2) but the count and progression toward a CISA advisory indicate a persistent security-architecture issue rather than one-off misuse. Index 17.8 and the 95.6th percentile reflect this recurring, multi-source pattern.
| Sev | Date | Type | Location | Incident | Source |
|---|---|---|---|---|---|
| S1 | 05/2025 | cyber | — | CISA advisory: Ecovacs Deebot base stations accept unvalidated firmware updates, deterministic WiFi key · Deebot Goat G1, Deebot 900/N8/T8 and r… | CISA |
| S2 | 08/2024 | cyber | — | Researchers demonstrate Bluetooth/PIN flaw letting attackers hijack Ecovacs Deebot cameras and mics · multiple Deebot models | Security Affairs |
| S2 | 05/2024 | cyber | — | Hacked Ecovacs Deebot X2 vacuums shout racial slurs, chase pet in multiple US cities · at least 2 households across multiple … | Tom's Guide |