S1 · 05/2025 · Ecovacs
| Company | Ecovacs |
| Category | consumer robotics |
| Type | cyber |
| Date | 05/2025 |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | S1 (near-miss / disclosed vulnerability) |
| Scale | Deebot Goat G1, Deebot 900/N8/T8 and related models |
| Confidence | high |
| Verification | Cited source on file; not independently re-verified |
| Source | CISA |
CISA published ICS advisory ICSA-25-135-19 describing vulnerabilities in Ecovacs Deebot vacuums and base stations, including base stations that do not validate firmware updates (allowing malicious OTA pushes) and a deterministic WPA2-PSK derivable from the device serial number. Ecovacs released patches; no known public exploitation was reported.