| Advisory ID | DC416-2026-0001 |
|---|---|
| CVE ID | Requested via MITRE CNA-LR — assignment pending |
| Status | Public — coordinated disclosure (embargo expired 2026-08-27) |
| CVSS v4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H (10.0 Critical) |
| CWE | CWE-285 (Improper Authorization), CWE-862 (Missing Authorization) |
| Vendor | Ecovacs Robotics Co., Ltd. |
| Affected | Ecovacs production MQTT brokers (mq-ww.ecouser.net and regional brokers) DEEBOT line including T30S (ecovacs.eqmf84) and T50 OMNI (ecovacs.mezar1) Production cloud as observed 2026-04-14 onward |
| Fixed in | Pending vendor confirmation |
| Credit | Amir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator) |
| Disclosed | 2026-10-04 |
| Machine-readable | DC416-2026-0001.json (CVE Record Format 5.1) |
The Ecovacs MQTT brokers do not enforce per-device publish authorization on the iot/p2p/shell topic tree. Any client holding a single valid Ecovacs credential can publish a shell command targeting any other device in the global DEEBOT fleet, and the on-device handler runs it as root.
A single foothold yields root remote code execution on any DEEBOT in the fleet, across customer trust boundaries, with no further escalation. Root on these edge devices reaches the owner's home network, microphones, cameras, and home-mapping data.
The broker does not bind the publishing client's authenticated device identifier (DID) to the source segment of the topic path, and does not verify that the client owns the target DID. A command published toward another customer's DID is delivered, and the on-device BUMBEE plugin executes the payload as root. The root cause is the broker authorization policy; the on-device execution is the second half of the chain.
None. The defect is in Ecovacs' centrally operated broker; device owners cannot mitigate it locally.
Bind every iot/p2p publication to the publishing client's authenticated DID at the broker and reject any publish whose source-DID segment does not match the connected client. As defence in depth, issue per-device signing keys at provisioning and verify a payload signature on-device before any execution, so a bypassed broker still fails closed.
This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.