All advisories
DC416 Security Advisory

MQTT broker ACL wildcard inversion exposes cross-tenant configuration push messages

HIGH · CVSS 7.1
Advisory IDDC416-2026-0002
CVE IDRequested via MITRE CNA-LR — assignment pending
StatusPublic — coordinated disclosure (embargo expired 2026-08-27)
CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N  (7.1 High)
CWECWE-863 (Incorrect Authorization), CWE-200 (Exposure of Sensitive Information)
VendorEcovacs Robotics Co., Ltd.
AffectedEcovacs production MQTT broker (mq-ww.ecouser.net) and regional brokers
ACL applied to the iot/cfg/ and iot/dtcfg/ topic trees
Production cloud as observed 2026-04-14 onward
Fixed inPending vendor confirmation
CreditAmir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator)
Disclosed2026-10-04
Machine-readableDC416-2026-0002.json (CVE Record Format 5.1)

Summary

The broker ACL grants the multi-level wildcard subscription iot/cfg/# to any authenticated client while denying the narrower iot/cfg/+. A single client therefore receives configuration-push messages addressed to every device in the global fleet.

Impact

One authenticated client collects fleet-wide configuration pushes, including firmware update URLs and certificate identifiers, together with the target device identifiers encoded in the topic path. This turns the broker into a fleet-wide config collector and a DID harvester that directly supplies targets for the fleet-wide RCE chain.

Technical details

The same wildcard inversion applies to iot/dtcfg/#. An ACL that grants a broad # while only intending to grant a narrower + is the core defect.

Proof of concept withheld. A six-hour passive subscription captured 147 unique fleet device identifiers and 412 configuration-push messages on researcher accounts. No public exploit code has been released. Testing was performed only on researcher-owned devices and accounts under an executed Safe Harbor agreement.

Mitigations for owners

None. The defect is in Ecovacs' centrally operated broker ACL.

Recommended vendor remediation

Reject iot/cfg/# and iot/dtcfg/# subscriptions outright and grant only fully qualified iot/cfg/{client_did} paths bound to the connection's DID. Audit every ACL rule so that for each granted + there is no broader granted # on the same tree.

Disclosure timeline

  • 2026-04-14Research begins against researcher-owned DEEBOT T30S and T50 OMNI and the Ecovacs cloud.
  • 2026-04-20Ecovacs Product Security first contacted (product-security@ecovacs.com).
  • 2026-04-28Safe Harbor Commitment Letter executed between the researcher and Ecovacs.
  • 2026-05-28Full technical report submitted to Ecovacs; CVE IDs requested from MITRE CNA-LR.
  • 2026-05-29Ecovacs confirms receipt of the technical report — start of the 90-day non-disclosure period (Day 0).
  • 2026-08-2790-day coordinated-disclosure embargo expires (Day 90).
  • 2026-10-04DC416 publishes these advisories. CVE IDs remain pending MITRE CNA-LR assignment.

References

Related advisories in this set

  • DC416-2026-0001 — Unauthenticated MQTT command injection yields fleet-wide root shell on Ecovacs DEEBOT devices
  • DC416-2026-0003 — Unauthenticated getVipUserId endpoint exposes a sequential user-account oracle
  • DC416-2026-0004 — devmanager.do confirms device IDs and leaks backend metadata through distinguishable errors
  • DC416-2026-0005 — Global login API distinguishes three account states, enabling unauthenticated email enumeration

This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.