ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.Referenceshttps://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.htmlhttps://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf