news

Ecovacs robot vacuum cleaner exposed to security flaws, can use camera and microphone to monitor owner

2024-08-10

한어Русский языкEnglishFrançaisIndonesianSanskrit日本語DeutschPortuguêsΕλληνικάespañolItalianoSuomalainenLatina

IT Home reported on August 10 that the technology media TechCrunch reported yesterday (August 9) that security researchers Dennis Giese and Braelynn will attend the Def Con hacker conference.Demonstrate and report Ecovacs robot vacuum cleaners and lawn mowers product vulnerabilities

The researchers said they contacted Ecovacs to report the vulnerabilities but never heard back from the company, and they believe the vulnerabilities remain unpatched and could be exploited by hackers.

Researchers said that the vulnerability can be exploited to connect to and take over the Ecovacs sweeping robot via Bluetooth, with the longest distance reaching 130 meters.

Moreover, once hackers take control of these sweeping robots, since they can connect to Wi-Fi networks themselves, they can be remotely connected and controlled later.

IT Home learned from the report that researchers said they could use the vulnerability to read Wi-Fi hotspot passwords, read all maps saved by the sweeping robot, and access components such as cameras and microphones.

Researchers say the following devices have security vulnerabilities

Ecovacs Deebot 900 Series

Ecovacs Deebot N8/T8

Ecovacs Deebot N9/T9

Ecovacs Deebot N10/T10

Ecovacs Deebot X1

Ecovacs Deebot T20

Ecovacs Deebot X2

Ecovacs Goat G1

Ecovacs Spybot Airbot Z1

Ecovacs Airbot AVA

Ecovacs Airbot ANDY