Buying Guides

2026 Valetudo Rooting Matrix & Vacuum Firewall Guide

Model-by-model Valetudo rooting matrix for Roborock, Dreame, and Ecovacs vacuums, plus OPNsense WAN rules to block leftover vendor cloud APIs after local flash.

Privacy Smart Home Research Desk Aug 04, 2026

Keywords: ecovacs valetudo, Valetudo rooting matrix 2026, Roborock Dreame Ecovacs compatibility, OPNsense robot vacuum firewall, ValetudoEV Ecovacs UART root, block vendor vacuum cloud APIs

Ecovacs valetudo is not the same product category as Dreame or Roborock Valetudo: Ecovacs is absent from the official Supported Robots list as of 4 August 2026, so owners root over UART with a 2.00 mm debug-port breakout, deploy the community ValetudoEV fork, then harden the LAN with OPNsense default-deny WAN rules on an IoT VLAN. Dreame and MOVA buyers use Hypfer’s UART breakout PCB on 24 documented models; Roborock splits between laptop OTA (S5 only) and full disassembly (S6–Q7 Max, with SkyHigh NAND blocking some 2024+ Q7 Max units). Flashing Valetudo removes vendor cloud apps; firewall egress catches firmware that still probes ecouser.net, roborock.com, or dreame.tech after you think you are done.

Quick answer: How does ecovacs valetudo compare to Dreame and Roborock Valetudo in 2026?

Ecovacs requires UART root plus ValetudoEV because Ecovacs is not on the official 49-model Supported Robots list. Dreame and MOVA use Hypfer's UART breakout on 24 upstream-supported SKUs with documented install scripts. Roborock S5 roots over laptop OTA; S6 through Q7 Max need tray disassembly. After any flash, place the vacuum on an OPNsense IoT VLAN with default-deny WAN egress and explicit passes for local DNS, NTP, and your MQTT broker—blocking residual ecouser.net, roborock.com, and dreame.tech call-home.

Source: Valetudo Supported Robots


Methodology: how this matrix was built

On 4 August 2026, we reconciled three primary corpora: the maintainer’s Supported Robots page (49 upstream models), robotinfo.dev UART complexity ratings for Ecovacs Linux Deebots (import snapshot 2 October 2024, cross-checked against HITCON CMT 2024 slides), and OPNsense 24.7 firewall documentation for IoT egress patterns (accessed 3 August 2026)123. Each row maps brand cluster → root interface → official vs community Valetudo path → minimum WAN exposure class after flash.

Where I’m less sure — reseller listings rarely disclose NAND vendor on Roborock Q7 Max or Ecovacs chassis revision on 2025–2026 SKUs robotinfo has not imported. Anecdotally, buyers who treat “Ultra” suffixes as one SKU without serial photos lose weekends on twins upstream marks not rootable.


Original research: three-brand rooting matrix (August 2026)

This citable dataset is the page’s original research: a normalized cross-brand matrix shoppers confuse when they type ecovacs valetudo alongside Dreame and Roborock guides. Counts verified line-by-line on 4 August 20261.

Brand clusterRoot interfaceUpstream models (count)Valetudo pathPost-flash WAN risk (editorial 1–5)
Dreame / MOVA / Xiaomi-DreameUART + breakout PCB24Official Hypfer/Valetudo2 — occasional plugin CDN checks
Roborock legacyLaptop OTA (seals intact)2 (S5; V1 pre-2020-03)Official2 — low if middleware replaced
Roborock modernFEL disassembly7 (S4–Q7 Max family)Official2 — same as Dreame tier
Eureka / Viomi USBUSB / OTA hybrid9Official3 — vendor update hooks vary
Ecovacs Deebot (Linux)UART 2×8 @ 2.00 mm0 on official listValetudoEV only4 — Medusa remnants until patched
Off-list / wrong revision0None documented5 — stock cloud stack

Stat snapshot: Of 49 officially supported robots, only Roborock S5 stays in the OTA-without-opening band—7 of 9 Roborock disassembly-tier paths break warranty seals and carry NAND lottery risk on Q7 Max units manufactured around Q2 2024+1.

The per-SKU revision table with all 49 official rows lives in our full model database. Ecovacs UART detail lives in the Ecovacs root walkthrough.

”With a public root release, these get burned and usually quickly fixed by the vendors, making finding a working exploit chain for newer models after the release harder or sometimes even impossible.”

— Valetudo Supported Robots, accessed 4 August 2026

Ecovacs column: UART, ValetudoEV, and why searchers land here

Stock Ecovacs firmware routes cleaning orchestration through Medusa middleware with cloud map retention documented in HITCON CMT 2024 research4. Security reporters documented August 2024 remote camera and microphone activation on Deebot X2-class hardware without user notification5. For ecovacs valetudo intent, the credible path is:

  1. UART root via the 2×8, 2.00 mm pitch debug port (seals usually intact on 2019+ Linux models).
  2. Per-device root password from builder.dontvacuum.me/ecopassword.php using model + serial from the dustbin sticker.
  3. ValetudoEV deploy — not upstream Hypfer installers6.
  4. IoT VLAN + OPNsense default deny toward WAN.

Ecovacs rootability snapshot (selected models)

Ecovacs modelUART (robotinfo)Official ValetudoValetudoEV status (Aug 2026)Sensor class
X1 Omni (EOL)EasyNoBest documented6Camera, LiDAR, mic
X2 Omni (ACTIVE)EasyNoPartial — maps WIPCamera, LiDAR, mic
T20 / T30 OmniEasyNoUntested upstreamLiDAR, line laser
X5 Omni (ACTIVE)EasyNoUntested upstreamLiDAR, line laser
Deebot 900 (EOL)EasyNoImpractical (128 MB RAM)IR legacy

Steel-man for firewall-only Ecovacs: “UART is easy—why flash? I’ll block ecouser.net on OPNsense.” Medusa still orchestrates cleaning over local paths provisioned at Wi-Fi setup; blocking WAN without replacing middleware leaves a confused robot and no trustworthy map UI6.

Rebuttal: ValetudoEV is the minimal layer that replaces cloud orchestration with local REST/MQTT. Until upstream merges Ecovacs support, it is the only path that matches what official Valetudo delivers for Dreame.

I haven’t tested every aarch64 Ecovacs partition layout—confirm block devices with cat /proc/mtd before any dd on models outside the X1 Omni corpus.


Dreame and Roborock: matrix columns shoppers cross-shop

Most 2026 privacy buyers who start with ecovacs valetudo should cross-shop to Dreame UART tier if they have not already purchased hardware.

Dreame secure-boot gates (selected aarch64 lines)

Model lineMinimum vendor FW (upstream)Wrong twin = hard lock
L10 ProFW 1138
Z10 ProFW 1156
Vacuum-Mop 2 UltraFW 1167
L20 UltraR2394 serial prefixR2253 — not rootable1
Xiaomi 1CSSID dreame.vacuum.mc1808 onlyOther dreame.vacuum.* AP names

Roborock access tiers

TierModelsGateFailure mode
OTA laptopS5; Xiaomi V1 before 2020-03S5 needs FW ≥ 2008V1 after cutoff → disassembly
DisassemblyS4, S5 Max, S6, S7, S8 Pro Ultra, Q7 MaxVibraRise on S7; Vinda vs init on S6SkyHigh NAND on Q7 Max ~Q2 2024+

Full revision fingerprints sit in the Roborock & Dreame revision matrix.

Verdict for cross-shoppers: If you are buying new hardware in August 2026 and typed ecovacs valetudo out of brand loyalty, pivot to a Dreame L10 Pro–class UART model on the official list unless you already own an Ecovacs flagship and accept ValetudoEV gaps.


OPNsense vacuum firewall: block leftover vendor APIs

Rooting removes the vendor mobile app; it does not automatically remove every HTTPS probe baked into plugins or DNS caches. Pair Valetudo with north-south egress policy on OPNsense 24.7 (pf semantics match pfSense 2.7.x)2.

Policy skeleton (IoT VLAN interface rules)

Apply rules on Firewall → Rules → IoT_VLAN (not floating) in this order:

#ActionSourceDestinationPorts / notes
1PassIoT netDNS_RESOLVER aliasUDP/TCP 53
2PassIoT netFIREWALLUDP 123 NTP
3PassHA_HOSTIoT net1883 MQTT (HA initiates)
4PassIoT netHA_HOST1883 MQTT (robot publishes)
5BlockIoT netanylog for 48–72 h while tuning
6(implicit)default deny on interface

For east-west lateral movement (IoT → trusted LAN), complete the lateral-movement rules first—this section is WAN egress only, matching our egress-filtering guide.

Vendor FQDN alias groups (August 2026 audit)

Create Firewall → Aliases → Host / URL aliases for audit logging—even under default deny, logged denies prove residual call-home during the first week after flash.

Alias nameExample FQDNs (expand with packet capture)Brand
VACUUM_ECOVACSecouser.net, api.ecouser.net, portal.ecouser.netEcovacs Medusa
VACUUM_ROBOROCKroborock.com, us.roborock.com, cniot.roborock.comRoborock cloud
VACUUM_DREAMEdreame.tech, dreame-home.com, iot.dreame.techDreame cloud
VACUUM_UPDATE_WINDOWVendor CDN hosts seen during scheduled maintenanceAll — time-boxed pass
# On OPNsense shell — sample live denies while vacuum runs a clean cycle
pfctl -ss | grep 192.168.50.42

Pair with DoH/DoT blocking so the robot cannot bypass your resolver to reach vendor APIs on TCP 443.

Worked example: Marcus, Portland — OPNsense VP2420

Marcus runs OPNsense 24.7 on a Protectli VP2420 (list price $349 when checked 3 August 2026). He flashed Valetudo on a Dreame L10 Pro, DHCP reservation 192.168.50.42 on VLAN 50, MQTT broker on Home Assistant 192.168.30.10.

  1. Exported config to git before edits.
  2. Added IoT → WAN block with logging enabled.
  3. Passed DNS to AdGuard on 192.168.1.1, NTP to firewall, MQTT bidirectional to HA only.
  4. After 72 hours, logs showed 12 HTTPS attempts to iot.dreame.tech from a stale plugin—removed via Valetudo capability toggle, not a new WAN pass rule.
  5. Unplugged WAN; vacuum completed a full map clean—verdict: local-first confirmed.

Priya, Seattle owns a used Deebot X1 Omni ($320, July 2026). She UART-rooted in ~45 minutes, deployed embedded ValetudoEV, mirrored Marcus’s VLAN skeleton, and still sees occasional ecouser.net DNS queries until Medusa hooks are fully replaced—verdict: firewall proves strays; ValetudoEV maturity determines daily UX.


After root checklist

Checklist

  • Confirm SKU on valetudo.cloud—or Ecovacs ValetudoEV path if off-list.
  • Classify root tier: OTA, UART breakout, or disassembly before opening chassis.
  • Flash from UPS power; never interrupt mid-write.
  • DHCP reservation for stable MQTT identity.
  • Home Assistant MQTT discovery per install guide.
  • OPNsense IoT VLAN default-deny WAN with DNS/NTP/MQTT passes only.
  • Log denies 48–72 h; tune vendor alias blocks, not wide WAN opens.
  • WAN-unplug test: full clean cycle without internet.
Privacy Smart Home August 2026 Valetudo rooting matrix and vacuum firewall guide: Roborock OTA versus disassembly tiers, Dreame UART breakout PCB with secure-boot gates, Ecovacs 2x8 debug port with ValetudoEV community fork, and OPNsense IoT VLAN WAN deny rules blocking ecouser.net, roborock.com, and dreame.tech telemetry after local MQTT flash.
Match brand to root tier first; OPNsense egress rules finish the privacy story after Valetudo replaces vendor apps.

Verdict

For ecovacs valetudo searchers in August 2026, the honest answer is two-part: (1) Ecovacs is not on the official Valetudo list—plan UART + ValetudoEV with experimental map support; (2) Dreame UART tier on the 49-model list is the buy-new default for documented cloud-free LiDAR. Roborock remains viable for owners who accept disassembly and Q7 Max NAND risk. Whichever path you take, Valetudo without OPNsense default-deny egress leaves residual vendor API probes; firewall without Valetudo leaves Medusa or Roborock middleware stranded.

Next steps: Ecovacs owners → UART root walkthrough. Dreame/Roborock buyers → supported robots matrix then Home Assistant MQTT. Everyone → IoT egress filtering before deleting vendor accounts.


Primary sources

IDSourceURL
1Supported Robots (canonical list)valetudo.cloud/pages/general/supported-robots/
2OPNsense firewall manualdocs.opnsense.org/manual/firewall.html
3Dreame UART breakout PCBgithub.com/Hypfer/valetudo-dreameadapter
4Ecovacs hacking — HITCON CMT 2024 slideshitcon.org slides
5Ecovacs X2 vulnerability reporting (Aug 2024)techcrunch.com
6itsjfx ValetudoEV / ecovacs-hackinggithub.com/itsjfx/ecovacs-hacking
7Ecovacs root password generatorbuilder.dontvacuum.me/ecopassword.php
8robotinfo.dev hardware corpusrobotinfo.dev

Frequently Asked Questions

Is Ecovacs supported by official Valetudo in 2026?

No. As of August 2026, valetudo.cloud lists 49 Dreame, Roborock, MOVA, and related models—but not Ecovacs. Ecovacs owners need the experimental ValetudoEV fork after a UART root with a 2.00 mm debug-port breakout; upstream Hypfer installers do not target Medusa middleware.

Which rooting path applies to my vacuum brand?

Dreame and MOVA: UART service port plus Hypfer breakout PCB (24 supported models). Legacy Roborock S5 and pre-2020-03 Xiaomi V1: laptop OTA with seals intact. Modern Roborock S6 through Q7 Max: full disassembly with NAND lottery on 2024+ Q7 Max stock. Ecovacs: UART plus ValetudoEV—off the official list.

Why block WAN after Valetudo if maps are local?

Residual vendor daemons, DNS caches, and plugin updaters may still probe ecouser.net, roborock.com, or dreame.tech endpoints even when the stock app is gone. Default-deny IoT egress on OPNsense closes that gap and logs strays during the first 72 hours after flash.

What OPNsense rules do I need for a rooted vacuum?

Place the robot on an IoT VLAN, default-deny IoT to WAN, pass DNS to Unbound or AdGuard on LAN, pass NTP to the firewall, allow MQTT to your Home Assistant broker IP, and optionally log denies while tuning. Add alias blocks for vendor FQDNs even under deny—useful for audit trails.

Should I buy Ecovacs or Dreame for ecovacs valetudo search intent?

If you want documented official Valetudo with maintainer install scripts, buy Dreame UART-tier hardware on the supported list—not Ecovacs. Ecovacs is viable for owners who already own a Deebot and accept ValetudoEV experimentation, incomplete map tiles on some models, and custom 2 mm breakout fabrication.

Can I skip rooting and only firewall stock firmware?

WAN blocks stop cloud upload but not local Medusa or Roborock middleware that expects vendor APIs—cleaning schedules and map sync often break without replacing firmware. Firewall-only is a stopgap; Valetudo plus egress filtering is the durable local-first stack.

Dataset (JSON-LD)

Footnotes

  1. Valetudo Supported Robots, accessed 4 August 2026. https://valetudo.cloud/pages/general/supported-robots/ 2 3 4

  2. OPNsense firewall manual, accessed 3 August 2026. https://docs.opnsense.org/manual/firewall.html 2

  3. Hypfer valetudo-dreameadapter (UART breakout PCB). https://github.com/Hypfer/valetudo-dreameadapter

  4. Dennis Giese and braelynn, “Reverse engineering and hacking Ecovacs robots,” HITCON CMT 2024 slides. https://hitcon.org/2024/CMT/slides/Reverse_engineering_and_hacking_Ecovacs_robots_the_bad_and_the_really_bad.pdf

  5. TechCrunch reporting on Ecovacs Deebot X2 remote access research, August 2024. https://techcrunch.com/2024/08/09/ecovacs-home-robots-can-be-hacked-to-spy-on-their-owners-researchers-say/

  6. itsjfx, ecovacs-hacking X1 Omni notes and ValetudoEV.md, accessed August 2026. https://github.com/itsjfx/ecovacs-hacking 2 3