| Advisory ID | DC416-2026-0004 |
|---|---|
| CVE ID | Requested via MITRE CNA-LR — assignment pending |
| Status | Public — coordinated disclosure (embargo expired 2026-08-27) |
| CVSS v4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N (5.3 Medium) |
| CWE | CWE-204 (Observable Response Discrepancy), CWE-209 (Generation of Error Message Containing Sensitive Information) |
| Vendor | Ecovacs Robotics Co., Ltd. |
| Affected | Ecovacs portal endpoint POST portal-ww.ecouser.net/api/iot/devmanager.do (and the api-ngiot.dc-na.ww.ecouser.net equivalent) Production cloud as observed 2026-04-14 onward |
| Fixed in | Pending vendor confirmation |
| Credit | Amir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator) |
| Disclosed | 2026-10-04 |
| Machine-readable | DC416-2026-0004.json (CVE Record Format 5.1) |
The devmanager.do endpoint returns distinguishable error codes for the four states of any queried device identifier, letting an authenticated low-privilege caller tell real device IDs from random ones, which real IDs the account does not own, and which are currently online.
The endpoint becomes a fleet-wide device-ID validation oracle that supports the enumeration feeding the fleet-wide RCE chain. Error responses also leak internal service names, internal timestamps, and internal task descriptors.
A sustained probe rate of roughly 50 requests per second was observed without throttling.
None. The defect is in a centrally operated Ecovacs portal endpoint.
Collapse the distinguishable states into one uniform error for any device the account does not own; remove internal service names, timestamps, and trace identifiers from production error bodies; and rate-limit distinct device-ID lookups per account.
This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.