Junglewise Threat Intelligence

CVE-2025-44251: Ecovacs Deebot T10 cleartext Wi-Fi credential transmission during pairing

CVE-2025-44251 · Severity: high · CVSS 7.5 · Published 2025-07-10

Vendors: Ecovacs.

Executive brief

The Ecovacs Deebot T10 robotic vacuum cleaner transmits the user's home Wi-Fi password in an unencrypted format during the initial setup and pairing process. An attacker physically near the device during setup could intercept this information by monitoring the temporary Wi-Fi network created by the vacuum. This could allow an unauthorized individual to gain access to the owner's private home network and any other connected devices.

Technical details

A cleartext transmission of sensitive information (CWE-319) exists in the Ecovacs Deebot T10 pairing workflow. During setup, the vacuum creates an unencrypted (open) Wi-Fi Access Point to communicate with the mobile application. The Ecovacs Home iOS app then transmits the user's home Wi-Fi SSID and password to the vacuum's /rcp.do endpoint using a cleartext HTTP POST request. An attacker within Wi-Fi range can sniff this traffic to obtain the credentials. Although the vendor claimed a server-side and app-side fix was deployed in mid-2025, researchers reported the vulnerability persisted in Deebot firmware 1.7.5 and iOS app 3.4.0.

Affected products

  • Ecovacs Deebot T10 1.7.2, 1.7.5
  • Ecovacs Ecovacs Home iOS App 3.0.0, 3.4.0

Timeline

  • 2024-11-13: disclosed: Initial contact with Ecovacs support.
  • 2024-12-04: other: Vulnerability confirmed by Ecovacs.
  • 2025-05-06: patched: Vendor claimed server-side and app updates were completed.
  • 2025-06-25: other: Researcher verified the vulnerability still exists in latest versions.
  • 2025-07-09: advisory: Public disclosure by researcher.
  • 2025-07-10: advisory: NVD publication date.

References