All advisories
DC416 Security Advisory

Unauthenticated getVipUserId endpoint exposes a sequential user-account oracle

MEDIUM · CVSS 6.9
Advisory IDDC416-2026-0003
CVE IDRequested via MITRE CNA-LR — assignment pending
StatusPublic — coordinated disclosure (embargo expired 2026-08-27)
CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N  (6.9 Medium)
CWECWE-204 (Observable Response Discrepancy), CWE-359 (Exposure of Private Personal Information)
VendorEcovacs Robotics Co., Ltd.
AffectedEcovacs portal endpoint POST portal.ecouser.net/api/users/user.do (todo=getVipUserId, country=cn)
Production cloud as observed 2026-04-14 onward
Fixed inPending vendor confirmation
CreditAmir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator)
Disclosed2026-10-04
Machine-readableDC416-2026-0003.json (CVE Record Format 5.1)

Summary

The getVipUserId portal endpoint requires no authentication. It returns a sequential numeric user ID when the supplied login name is registered and a fixed "no such user" error otherwise.

Impact

The two response paths form an unauthenticated account-existence oracle, and the sequential numeric ID additionally leaks the chronological ordering and approximate size of the user base. The oracle supports credential-stuffing pre-filtering and phishing target selection.

Technical details

Probing at several requests per second from a single source was observed without rate limiting or a CAPTCHA challenge.

Proof of concept withheld. Demonstrated with sample probes on researcher-controlled values. No public exploit code has been released. Testing was performed only on researcher-owned devices and accounts under an executed Safe Harbor agreement.

Mitigations for owners

None. The defect is in a centrally operated Ecovacs portal endpoint.

Recommended vendor remediation

Reject unauthenticated requests and scope the lookup to internal services or admin sessions; strip the numeric user ID from responses; return identical bodies and status codes for found and not-found accounts; and apply per-source rate limiting.

Disclosure timeline

  • 2026-04-14Research begins against researcher-owned DEEBOT T30S and T50 OMNI and the Ecovacs cloud.
  • 2026-04-20Ecovacs Product Security first contacted (product-security@ecovacs.com).
  • 2026-04-28Safe Harbor Commitment Letter executed between the researcher and Ecovacs.
  • 2026-05-28Full technical report submitted to Ecovacs; CVE IDs requested from MITRE CNA-LR.
  • 2026-05-29Ecovacs confirms receipt of the technical report — start of the 90-day non-disclosure period (Day 0).
  • 2026-08-2790-day coordinated-disclosure embargo expires (Day 90).
  • 2026-10-04DC416 publishes these advisories. CVE IDs remain pending MITRE CNA-LR assignment.

References

Related advisories in this set

  • DC416-2026-0001 — Unauthenticated MQTT command injection yields fleet-wide root shell on Ecovacs DEEBOT devices
  • DC416-2026-0002 — MQTT broker ACL wildcard inversion exposes cross-tenant configuration push messages
  • DC416-2026-0004 — devmanager.do confirms device IDs and leaks backend metadata through distinguishable errors
  • DC416-2026-0005 — Global login API distinguishes three account states, enabling unauthenticated email enumeration

This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.