|
|
|
|
|
by dikkechill
630 days ago
|
|
I found the open source Valetudo (https://github.com/Hypfer/Valetudo) project quite interesting, as it sits between the vendor firmware and (cloud) connectivity. The project is made possible due to Dennis Giese's research. It currently supports Dreame, Xiaomi, Roborock and some others. But not Ecovacs.
And not sure it prevents this type of Bluetooth vulnerabilities. |
|
> As you might know, we looked into Ecovacs as an alternative for Dreame&Roborock. However, we found security and privacy being completely broken. If you have a X2, a Goat lawnmower, or newer than 2023 devices, you might want to turn them off for now. There is a BLE RCE, that lets an unauthenticated attacker send a payload via Bluetooth, that gets executed as root on the device. It does not appear that Ecovacs wants to fix that. More information: https://twitter.com/lorenzofb/status/1822002515279270079 https://techcrunch.com/2024/08/09/ecovacs-home-robots-can-be...