RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / Ecovacs / 2025-05

CISA advisory: Ecovacs Deebot base stations accept unvalidated firmware updates, deterministic WiFi key

S1 · 05/2025 · Ecovacs

Record

CompanyEcovacs
Categoryconsumer robotics
Typecyber
Date05/2025
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS1 (near-miss / disclosed vulnerability)
ScaleDeebot Goat G1, Deebot 900/N8/T8 and related models
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceCISA

What happened

CISA published ICS advisory ICSA-25-135-19 describing vulnerabilities in Ecovacs Deebot vacuums and base stations, including base stations that do not validate firmware updates (allowing malicious OTA pushes) and a deterministic WPA2-PSK derivable from the device serial number. Ecovacs released patches; no known public exploitation was reported.

Ecovacs record context

Entries by year and severity

122024 S2: 22242025 S1: 1125
S1S2S3S4S5

By incident type

By severity

Ecovacs vs consumer robotics alternatives

consumer robotics context

consumer robotics: entries by year

252018 S1: 11182020 S3: 11202021 S1: 11212022 S3: 11222023 S3: 22232024 S2: 22024 S4: 13242025 S1: 12025 S2: 23252026 S2: 12026 S3: 12026 S4: 12026 S5: 2526
S1S2S3S4S5

consumer robotics: failure modes

consumer robotics: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in consumer robotics

SevDateCompanyEvent
S52026-07-13SharkNinjaShark robot vacuum flaw allows remote code execution via stolen certificate
S22026-05YarboSecurity vulnerability exposed in ~6,000 Yarbo robot lawn mowers
S22025-09-02Dreame TechnologySecurity flaws found in Dreame (and Ecovacs) robot vacuums with cameras
S22024-08EcovacsResearchers demonstrate Bluetooth/PIN flaw letting attackers hijack Ecovacs Deebot cameras and mics
S22024-05EcovacsHacked Ecovacs Deebot X2 vacuums shout racial slurs, chase pet in multiple US cities
S12021-09-15RoborockRoborock discloses insecure random-number generator flaw in Tuya IoT cloud connection
S12018-05-29SoftBank RoboticsSecurity researchers find Pepper robot lacks basic authentication/security controls

Other Ecovacs entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs