All advisories
DC416 Security Advisory

devmanager.do confirms device IDs and leaks backend metadata through distinguishable errors

MEDIUM · CVSS 5.3
Advisory IDDC416-2026-0004
CVE IDRequested via MITRE CNA-LR — assignment pending
StatusPublic — coordinated disclosure (embargo expired 2026-08-27)
CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N  (5.3 Medium)
CWECWE-204 (Observable Response Discrepancy), CWE-209 (Generation of Error Message Containing Sensitive Information)
VendorEcovacs Robotics Co., Ltd.
AffectedEcovacs portal endpoint POST portal-ww.ecouser.net/api/iot/devmanager.do (and the api-ngiot.dc-na.ww.ecouser.net equivalent)
Production cloud as observed 2026-04-14 onward
Fixed inPending vendor confirmation
CreditAmir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator)
Disclosed2026-10-04
Machine-readableDC416-2026-0004.json (CVE Record Format 5.1)

Summary

The devmanager.do endpoint returns distinguishable error codes for the four states of any queried device identifier, letting an authenticated low-privilege caller tell real device IDs from random ones, which real IDs the account does not own, and which are currently online.

Impact

The endpoint becomes a fleet-wide device-ID validation oracle that supports the enumeration feeding the fleet-wide RCE chain. Error responses also leak internal service names, internal timestamps, and internal task descriptors.

Technical details

A sustained probe rate of roughly 50 requests per second was observed without throttling.

Proof of concept withheld. Demonstrated against owned, foreign, and random device identifiers on researcher accounts. No public exploit code has been released. Testing was performed only on researcher-owned devices and accounts under an executed Safe Harbor agreement.

Mitigations for owners

None. The defect is in a centrally operated Ecovacs portal endpoint.

Recommended vendor remediation

Collapse the distinguishable states into one uniform error for any device the account does not own; remove internal service names, timestamps, and trace identifiers from production error bodies; and rate-limit distinct device-ID lookups per account.

Disclosure timeline

  • 2026-04-14Research begins against researcher-owned DEEBOT T30S and T50 OMNI and the Ecovacs cloud.
  • 2026-04-20Ecovacs Product Security first contacted (product-security@ecovacs.com).
  • 2026-04-28Safe Harbor Commitment Letter executed between the researcher and Ecovacs.
  • 2026-05-28Full technical report submitted to Ecovacs; CVE IDs requested from MITRE CNA-LR.
  • 2026-05-29Ecovacs confirms receipt of the technical report — start of the 90-day non-disclosure period (Day 0).
  • 2026-08-2790-day coordinated-disclosure embargo expires (Day 90).
  • 2026-10-04DC416 publishes these advisories. CVE IDs remain pending MITRE CNA-LR assignment.

References

Related advisories in this set

  • DC416-2026-0001 — Unauthenticated MQTT command injection yields fleet-wide root shell on Ecovacs DEEBOT devices
  • DC416-2026-0002 — MQTT broker ACL wildcard inversion exposes cross-tenant configuration push messages
  • DC416-2026-0003 — Unauthenticated getVipUserId endpoint exposes a sequential user-account oracle
  • DC416-2026-0005 — Global login API distinguishes three account states, enabling unauthenticated email enumeration

This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.