CVE-2024-52328 Information

Description

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.

Reference

https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf url https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf url

Share on: