All advisories
DC416 Security Advisory

Global login API distinguishes three account states, enabling unauthenticated email enumeration

MEDIUM · CVSS 6.9
Advisory IDDC416-2026-0005
CVE IDRequested via MITRE CNA-LR — assignment pending
StatusPublic — coordinated disclosure (embargo expired 2026-08-27)
CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N  (6.9 Medium)
CWECWE-204 (Observable Response Discrepancy)
VendorEcovacs Robotics Co., Ltd.
AffectedEcovacs global login API at gl-{country}-api.ecovacs.com
Production cloud as observed 2026-04-14 onward
Fixed inPending vendor confirmation
CreditAmir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator)
Disclosed2026-10-04
Machine-readableDC416-2026-0005.json (CVE Record Format 5.1)

Summary

For an email submitted with a wrong password, the global login API returns three distinguishable responses: no account, account exists and is not locked, and account exists and is locked.

Impact

A single failed login probe is an account-state oracle that supports credential-stuffing pre-filtering and phishing target selection. The "one more attempt" message also confirms remaining lockout attempts.

Technical details

No CAPTCHA was issued during probe sequences against the endpoint.

Proof of concept withheld. Demonstrated on a researcher account. No public exploit code has been released. Testing was performed only on researcher-owned devices and accounts under an executed Safe Harbor agreement.

Mitigations for owners

None. The defect is in a centrally operated Ecovacs login endpoint.

Recommended vendor remediation

Return a single uniform response for unknown-account, wrong-password, and locked-account states; apply progressive delays and lockouts keyed on the email rather than the source IP; and alert and throttle on a source that probes many distinct emails in a short window.

Disclosure timeline

  • 2026-04-14Research begins against researcher-owned DEEBOT T30S and T50 OMNI and the Ecovacs cloud.
  • 2026-04-20Ecovacs Product Security first contacted (product-security@ecovacs.com).
  • 2026-04-28Safe Harbor Commitment Letter executed between the researcher and Ecovacs.
  • 2026-05-28Full technical report submitted to Ecovacs; CVE IDs requested from MITRE CNA-LR.
  • 2026-05-29Ecovacs confirms receipt of the technical report — start of the 90-day non-disclosure period (Day 0).
  • 2026-08-2790-day coordinated-disclosure embargo expires (Day 90).
  • 2026-10-04DC416 publishes these advisories. CVE IDs remain pending MITRE CNA-LR assignment.

References

Related advisories in this set

  • DC416-2026-0001 — Unauthenticated MQTT command injection yields fleet-wide root shell on Ecovacs DEEBOT devices
  • DC416-2026-0002 — MQTT broker ACL wildcard inversion exposes cross-tenant configuration push messages
  • DC416-2026-0003 — Unauthenticated getVipUserId endpoint exposes a sequential user-account oracle
  • DC416-2026-0004 — devmanager.do confirms device IDs and leaks backend metadata through distinguishable errors

This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.