| Advisory ID | DC416-2026-0003 |
|---|---|
| CVE ID | Requested via MITRE CNA-LR — assignment pending |
| Status | Public — coordinated disclosure (embargo expired 2026-08-27) |
| CVSS v4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N (6.9 Medium) |
| CWE | CWE-204 (Observable Response Discrepancy), CWE-359 (Exposure of Private Personal Information) |
| Vendor | Ecovacs Robotics Co., Ltd. |
| Affected | Ecovacs portal endpoint POST portal.ecouser.net/api/users/user.do (todo=getVipUserId, country=cn) Production cloud as observed 2026-04-14 onward |
| Fixed in | Pending vendor confirmation |
| Credit | Amir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator) |
| Disclosed | 2026-10-04 |
| Machine-readable | DC416-2026-0003.json (CVE Record Format 5.1) |
The getVipUserId portal endpoint requires no authentication. It returns a sequential numeric user ID when the supplied login name is registered and a fixed "no such user" error otherwise.
The two response paths form an unauthenticated account-existence oracle, and the sequential numeric ID additionally leaks the chronological ordering and approximate size of the user base. The oracle supports credential-stuffing pre-filtering and phishing target selection.
Probing at several requests per second from a single source was observed without rate limiting or a CAPTCHA challenge.
None. The defect is in a centrally operated Ecovacs portal endpoint.
Reject unauthenticated requests and scope the lookup to internal services or admin sessions; strip the numeric user ID from responses; return identical bodies and status codes for found and not-found accounts; and apply per-source rate limiting.
This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.