{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "cveMetadata": {
    "cveId": "CVE ID pending (requested via MITRE CNA-LR)",
    "state": "PENDING"
  },
  "containers": {
    "cna": {
      "title": "DC416-2026-0001: Unauthenticated MQTT command injection yields fleet-wide root shell on Ecovacs DEEBOT devices",
      "x_advisoryId": "DC416-2026-0001",
      "x_advisoryUrl": "https://defcontoronto.ca/advisories/DC416-2026-0001.html",
      "descriptions": [
        {
          "lang": "en",
          "value": "The Ecovacs MQTT brokers do not enforce per-device publish authorization on the iot/p2p/shell topic tree. Any client holding a single valid Ecovacs credential can publish a shell command targeting any other device in the global DEEBOT fleet, and the on-device handler runs it as root. The broker does not bind the publishing client's authenticated device identifier (DID) to the source segment of the topic path, and does not verify that the client owns the target DID. A command published toward another customer's DID is delivered, and the on-device BUMBEE plugin executes the payload as root. The root cause is the broker authorization policy; the on-device execution is the second half of the chain."
        }
      ],
      "affected": [
        {
          "vendor": "Ecovacs Robotics Co., Ltd.",
          "product": "Ecovacs production MQTT brokers (mq-ww.ecouser.net and regional brokers)",
          "defaultStatus": "affected",
          "versions": [
            {
              "status": "affected",
              "version": "production cloud as of 2026-04-14"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "cweId": "CWE-285",
              "type": "CWE",
              "description": "CWE-285"
            },
            {
              "lang": "en",
              "cweId": "CWE-862",
              "type": "CWE",
              "description": "CWE-862"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "cvssV4_0": {
            "version": "4.0",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
            "baseScore": 10.0,
            "baseSeverity": "CRITICAL"
          }
        }
      ],
      "references": [
        {
          "url": "https://defcontoronto.ca/advisories/DC416-2026-0001.html"
        },
        {
          "url": "https://defcontoronto.ca/blog-ecovacs-deebot-fleet.html"
        },
        {
          "url": "https://www.ecovacs.com/global/security"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Amir Hosseinpour (independent security researcher)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "DEF CON Toronto (DC416)"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      }
    }
  }
}