| Advisory ID | DC416-2026-0005 |
|---|---|
| CVE ID | Requested via MITRE CNA-LR — assignment pending |
| Status | Public — coordinated disclosure (embargo expired 2026-08-27) |
| CVSS v4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N (6.9 Medium) |
| CWE | CWE-204 (Observable Response Discrepancy) |
| Vendor | Ecovacs Robotics Co., Ltd. |
| Affected | Ecovacs global login API at gl-{country}-api.ecovacs.com Production cloud as observed 2026-04-14 onward |
| Fixed in | Pending vendor confirmation |
| Credit | Amir Hosseinpour (finder) · DEF CON Toronto / DC416 (coordinator) |
| Disclosed | 2026-10-04 |
| Machine-readable | DC416-2026-0005.json (CVE Record Format 5.1) |
For an email submitted with a wrong password, the global login API returns three distinguishable responses: no account, account exists and is not locked, and account exists and is locked.
A single failed login probe is an account-state oracle that supports credential-stuffing pre-filtering and phishing target selection. The "one more attempt" message also confirms remaining lockout attempts.
No CAPTCHA was issued during probe sequences against the endpoint.
None. The defect is in a centrally operated Ecovacs login endpoint.
Return a single uniform response for unknown-account, wrong-password, and locked-account states; apply progressive delays and lockouts keyed on the email rather than the source IP; and alert and throttle on a source that probes many distinct emails in a short window.
This vulnerability was coordinated and published by DEF CON Toronto (DC416) under its vulnerability disclosure policy. A CVE identifier has been requested from MITRE CNA-LR and this advisory will be updated with the assigned CVE ID. Report security issues to cve@defcontoronto.ca.