| Advisory ID | DC416-2026-0002 |
|---|---|
| CVE ID | Requested via MITRE CNA-LR — assignment pending |
| Status | Public — coordinated disclosure (embargo expired 2026-08-27) |
| CVSS v4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N (7.1 High) |
| CWE | CWE-863 (Incorrect Authorization), CWE-200 (Exposure of Sensitive Information) |
| Vendor | Ecovacs Robotics Co., Ltd. |
| Affected | Ecovacs production MQTT broker (mq-ww.ecouser.net) and regional brokers ACL applied to the iot/cfg/ and iot/dtcfg/ topic trees Production cloud as observed 2026-04-14 onward |
| Fixed in | Pending vendor confirmation |
| Credit | Amir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator) |
| Disclosed | 2026-10-04 |
| Machine-readable | DC416-2026-0002.json (CVE Record Format 5.1) |
The broker ACL grants the multi-level wildcard subscription iot/cfg/# to any authenticated client while denying the narrower iot/cfg/+. A single client therefore receives configuration-push messages addressed to every device in the global fleet.
One authenticated client collects fleet-wide configuration pushes, including firmware update URLs and certificate identifiers, together with the target device identifiers encoded in the topic path. This turns the broker into a fleet-wide config collector and a DID harvester that directly supplies targets for the fleet-wide RCE chain.
The same wildcard inversion applies to iot/dtcfg/#. An ACL that grants a broad # while only intending to grant a narrower + is the core defect.
None. The defect is in Ecovacs' centrally operated broker ACL.
Reject iot/cfg/# and iot/dtcfg/# subscriptions outright and grant only fully qualified iot/cfg/{client_did} paths bound to the connection's DID. Audit every ACL rule so that for each granted + there is no broader granted # on the same tree.
This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.