Executive brief
The Ecovacs Deebot T10 robotic vacuum cleaner transmits the user's home Wi-Fi password in an unencrypted format during the initial setup and pairing process. An attacker physically near the device during setup could intercept this information by monitoring the temporary Wi-Fi network created by the vacuum. This could allow an unauthorized individual to gain access to the owner's private home network and any other connected devices.
Technical details
A cleartext transmission of sensitive information (CWE-319) exists in the Ecovacs Deebot T10 pairing workflow. During setup, the vacuum creates an unencrypted (open) Wi-Fi Access Point to communicate with the mobile application. The Ecovacs Home iOS app then transmits the user's home Wi-Fi SSID and password to the vacuum's /rcp.do endpoint using a cleartext HTTP POST request. An attacker within Wi-Fi range can sniff this traffic to obtain the credentials. Although the vendor claimed a server-side and app-side fix was deployed in mid-2025, researchers reported the vulnerability persisted in Deebot firmware 1.7.5 and iOS app 3.4.0.
Affected products
- Ecovacs Deebot T10 1.7.2, 1.7.5
- Ecovacs Ecovacs Home iOS App 3.0.0, 3.4.0
Timeline
- 2024-11-13: disclosed: Initial contact with Ecovacs support.
- 2024-12-04: other: Vulnerability confirmed by Ecovacs.
- 2025-05-06: patched: Vendor claimed server-side and app updates were completed.
- 2025-06-25: other: Researcher verified the vulnerability still exists in latest versions.
- 2025-07-09: advisory: Public disclosure by researcher.
- 2025-07-10: advisory: NVD publication date.