Security Advisory - Bluetooth Remote Code Execution (BLE RCE) Vulnerability in Goat Product Series
Initial Release Date: November 30, 2024Update Date: November 30, 2024
Vulnerability Overview
A Bluetooth Remote Code Execution (BLE RCE) vulnerability has been identified in ECOVACS' Goat product series. Under specific technical conditions, successful exploitation of this vulnerability could allow an attacker to remotely compromise the affected devices.
Vulnerability Source
The vulnerability information was provided by Dennis Giese, Braelynn Luedtke, and Chris Anderson. We sincerely appreciate their contributions to the security of ECOVACS products.
Versions and Fixes
Affected Products | Patched Versions |
GOAT G1-2000 | 1.36.187 |
GOAT G1 | 1.36.187 |
GOAT G1-800 | 1.36.187 |
GX-600 | 1.2.120 |
Version Access
Devices that support automatic updates will receive system update notifications. We have proactively pushed the update to all users. Users can complete the fix by performing the system update.
FAQs
None.
Security Incident Response
ECOVACS is committed to ensuring the best interests of our product users. We adhere to responsible disclosure principles and address security issues through our product security management process.
To report security issues related to ECOVACS products and solutions, please contact us at: product-security@ecovacs.com
ECOVACS will continue to monitor developments related to this vulnerability. Ongoing investigations are still in progress. If there are any changes, this advisory will be updated promptly. Please stay tuned for further updates.