CVE-2024-11147 Information
Jan 25, 2025
cve
Description
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
Reference
https://builder.dontvacuum.me/ecopassword.php url https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf url https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf url
Share on: