All advisories
DC416 Security Advisory

Unauthenticated MQTT command injection yields fleet-wide root shell on Ecovacs DEEBOT devices

CRITICAL · CVSS 10.0
Advisory IDDC416-2026-0001
CVE IDRequested via MITRE CNA-LR — assignment pending
StatusPublic — coordinated disclosure (embargo expired 2026-08-27)
CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H  (10.0 Critical)
CWECWE-285 (Improper Authorization), CWE-862 (Missing Authorization)
VendorEcovacs Robotics Co., Ltd.
AffectedEcovacs production MQTT brokers (mq-ww.ecouser.net and regional brokers)
DEEBOT line including T30S (ecovacs.eqmf84) and T50 OMNI (ecovacs.mezar1)
Production cloud as observed 2026-04-14 onward
Fixed inPending vendor confirmation
CreditAmir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator)
Disclosed2026-10-04
Machine-readableDC416-2026-0001.json (CVE Record Format 5.1)

Summary

The Ecovacs MQTT brokers do not enforce per-device publish authorization on the iot/p2p/shell topic tree. Any client holding a single valid Ecovacs credential can publish a shell command targeting any other device in the global DEEBOT fleet, and the on-device handler runs it as root.

Impact

A single foothold yields root remote code execution on any DEEBOT in the fleet, across customer trust boundaries, with no further escalation. Root on these edge devices reaches the owner's home network, microphones, cameras, and home-mapping data.

Technical details

The broker does not bind the publishing client's authenticated device identifier (DID) to the source segment of the topic path, and does not verify that the client owns the target DID. A command published toward another customer's DID is delivered, and the on-device BUMBEE plugin executes the payload as root. The root cause is the broker authorization policy; the on-device execution is the second half of the chain.

Proof of concept withheld. End-to-end exploitation was confirmed from a non-owning account against researcher-owned devices only. No public exploit code or weaponised tooling has been released. Testing was performed only on researcher-owned devices and accounts under an executed Safe Harbor agreement.

Mitigations for owners

None. The defect is in Ecovacs' centrally operated broker; device owners cannot mitigate it locally.

Recommended vendor remediation

Bind every iot/p2p publication to the publishing client's authenticated DID at the broker and reject any publish whose source-DID segment does not match the connected client. As defence in depth, issue per-device signing keys at provisioning and verify a payload signature on-device before any execution, so a bypassed broker still fails closed.

Disclosure timeline

  • 2026-04-14Research begins against researcher-owned DEEBOT T30S and T50 OMNI and the Ecovacs cloud.
  • 2026-04-20Ecovacs Product Security first contacted (product-security@ecovacs.com).
  • 2026-04-28Safe Harbor Commitment Letter executed between the researcher and Ecovacs.
  • 2026-05-28Full technical report submitted to Ecovacs; CVE IDs requested from MITRE CNA-LR.
  • 2026-05-29Ecovacs confirms receipt of the technical report — start of the 90-day non-disclosure period (Day 0).
  • 2026-08-2790-day coordinated-disclosure embargo expires (Day 90).
  • 2026-10-04DC416 publishes these advisories. CVE IDs remain pending MITRE CNA-LR assignment.

References

Related advisories in this set

  • DC416-2026-0002 — MQTT broker ACL wildcard inversion exposes cross-tenant configuration push messages
  • DC416-2026-0003 — Unauthenticated getVipUserId endpoint exposes a sequential user-account oracle
  • DC416-2026-0004 — devmanager.do confirms device IDs and leaks backend metadata through distinguishable errors
  • DC416-2026-0005 — Global login API distinguishes three account states, enabling unauthenticated email enumeration

This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.