← GrokBot Source Archive

LC-3 · Consumer Risk Bulletins

Kinematic Risk Consumer Bulletin

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-3/monthly-2020-2026/2025/KRCB-2025-05.md
Imported-content SHA-256
32ebd374c66a35998b277cdfd21f47b0a46c4577fcd11f900bef10548fee44d1
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# Kinematic Risk Consumer Bulletin

**LRRK Watch / Open-Source Intelligence** — Consumer kinematic electronics. Monthly filing.

**Issue type.** Monthly KRCB (retrospective). LC-3 (Consumer). Not the weekday 24–48h poll.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 May 2025 |
| Window | 1–31 May 2025 |
| Written | 19 August 2026 (retrospective reconstruction) |
| Data label | Open-source intelligence // LRRK analytic product // retrospective monthly filing |
| Handling | Public-source material. Image rights require separate verification before publication. |
| Scope | Consumer kinematic electronics only (home, yard, companion, educational). |
| Classes in frame | Robot vacuums / mop combos · robotic lawn mowers · window-cleaning robots · pool-cleaning robots · robot pets / companion animals · social / desk companions · educational / programmable kits · robotic litter boxes · security / home patrol robots · consumer robotic arms · elder-care / assistive companions · kitchen / food-prep robots · toy / entertainment robots · niche outdoor / garden robots · emerging general-purpose or humanoid home robots |
| Spine | Reputable channels for injury, death, incidents, and safety recalls (CPSC, Health Canada, EU Safety Gate, UK OPSS, manufacturer recall pages, named newsrooms, dockets). |
| Color | Message boards, consumer forums, and Reddit — annotated context only. Never Fact without a reputable primary. |

## Executive read

### BLUF

A mass-market camera robot became a US industrial-control advisory. Ecovacs published a DEEBOT base-station advisory on 8 May; CISA published ICSA-25-135-19 on 15 May. This filing states impact only. No exploit steps.

### Key judgments

1. **[Assessment — High confidence]** ICSA-25-135-19 is the first US ICS advisory this collection treats as attached to a mass-market home robot.
2. **[Assessment — High confidence]** CISA’s impact sentence is that successful exploitation “could allow an attacker to send malicious updates to the devices or execute code.” “No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.”
3. **[Inference — Moderate confidence]** Serial-derived keys and unsigned dock OTA will recur on other white-label docks. Patch uptake in the installed base is unknown.

### Analytic labels
- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades
- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution (typical for forums)

---

## 01. Ecovacs DEEBOT — vendor advisory 8 May; CISA ICSA-25-135-19 on 15 May

*Event / publication dates: Ecovacs DSA 8 May 2025; CISA ICSA-25-135-19 initial publication 15 May 2025*

**Product class.** Robot vacuums / mop combos

**Verified record — [Fact — A1]** Ecovacs published “Security Advisory — Base station communication security issues of DEEBOT series products” on **8 May 2025** (CVE-2025-30198, CVE-2025-30199, CVE-2025-30200). Researchers named: Dennis Giese, Braelynn Luedtke, Chris Anderson. Affected families and patched versions as listed by the vendor: X1S PRO and X1 PRO OMNI prior to 2.5.38; X1 OMNI and X1 TURBO prior to 2.4.45; T10 series prior to 1.11.0; T20 series prior to 1.25.0; T30 series prior to 1.100.0. Vendor: devices that support automatic updates will receive notifications; the company says it has pushed the update. Source: [Ecovacs DSA](https://www.ecovacs.com/global/userhelp/dsa20250509001).

CISA published **ICSA-25-135-19** on **15 May 2025**. Equipment: ECOVACS DEEBOT vacuum and base station. Vulnerabilities as labeled: use of hard-coded cryptographic key; download of code without integrity check. CVSS v4 **8.6**. Impact as written: successful exploitation “could allow an attacker to send malicious updates to the devices or execute code.” CISA: “No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.” This filing **states impact only**. It does **not** reproduce exploit steps, payloads, or reproduction procedures. Source: [CISA ICSA-25-135-19](https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-19).

**Threat landscape.** A floor-level camera robot and its dock. The trust objects on the official pages are indicator-and-update integrity and leftover control of the dock, not a proven retail footage sale. Physical harm is not alleged on these pages.

**Forum / community notes.**
- none independently confirmed this month. 2024 DEF CON 32 reporting is prior-window lineage and is not re-counted as a May signal.

**Intelligence assessment.** [Assessment — High confidence] This is the official residue of the 2024 camera-robot work: a vendor advisory plus a US ICS page. [Inference — Moderate confidence] Unsigned dock OTA will recur. [Uncertainty] Patch uptake. CISA’s “no known public exploitation” is a statement as of publication, not a finding that none will occur.

**Opportunity.** Update A (mitigation for all listed devices) is the next official line to watch. Lab should treat leftover-token and camera-on indicator integrity as first-class tests; those 2024 research claims are not restated as May Facts from the CISA page.

**LRRK relevance.** Control Fabric and Campaign (who may command the dock). Passport: signed OTA, key derivation, patch version. Watch: ICSA-25-135-19 for known-exploited status. Kestrel: only if a later firmware build claims a trustworthy camera-on tell.

**Confidence.** High on the existence, dates, CVE IDs, affected families, and CISA impact sentence. Moderate on vendor “all users are covered.” Low on installed-base patch uptake.

---

## Forward indicators

Ranked watchlist as of 31 May 2025.

1. CISA update stating mitigation for all listed devices.
2. Whether ICSA-25-135-19 is added to a known-exploited catalog.
3. Any CPSC or Health Canada physical-harm file on DEEBOT (none found).
4. Whether the January Autoscooper 11 death is filed.
5. Scuba S1 / Zodiac field aging.

> **Collection integrity.** Impact only: no exploit steps, payloads, or reproduction procedures are included. 2024 TechCrunch / DEF CON reporting is prior-window and was not used as a May Fact. No official pool-robot or litter-box action dated May 2025 was found. No floor robot-vac fire recall was found.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C3</span></p>