Buying Guides
2026 Valetudo Rooting Matrix & Vacuum Firewall Guide
Model-by-model Valetudo rooting matrix for Roborock, Dreame, and Ecovacs vacuums, plus OPNsense WAN rules to block leftover vendor cloud APIs after local flash.
Ecovacs valetudo is not the same product category as Dreame or Roborock Valetudo: Ecovacs is absent from the official Supported Robots list as of 4 August 2026, so owners root over UART with a 2.00 mm debug-port breakout, deploy the community ValetudoEV fork, then harden the LAN with OPNsense default-deny WAN rules on an IoT VLAN. Dreame and MOVA buyers use Hypfer’s UART breakout PCB on 24 documented models; Roborock splits between laptop OTA (S5 only) and full disassembly (S6–Q7 Max, with SkyHigh NAND blocking some 2024+ Q7 Max units). Flashing Valetudo removes vendor cloud apps; firewall egress catches firmware that still probes ecouser.net, roborock.com, or dreame.tech after you think you are done.
Quick answer: How does ecovacs valetudo compare to Dreame and Roborock Valetudo in 2026?
Ecovacs requires UART root plus ValetudoEV because Ecovacs is not on the official 49-model Supported Robots list. Dreame and MOVA use Hypfer's UART breakout on 24 upstream-supported SKUs with documented install scripts. Roborock S5 roots over laptop OTA; S6 through Q7 Max need tray disassembly. After any flash, place the vacuum on an OPNsense IoT VLAN with default-deny WAN egress and explicit passes for local DNS, NTP, and your MQTT broker—blocking residual ecouser.net, roborock.com, and dreame.tech call-home.
Source: Valetudo Supported Robots
Methodology: how this matrix was built
On 4 August 2026, we reconciled three primary corpora: the maintainer’s Supported Robots page (49 upstream models), robotinfo.dev UART complexity ratings for Ecovacs Linux Deebots (import snapshot 2 October 2024, cross-checked against HITCON CMT 2024 slides), and OPNsense 24.7 firewall documentation for IoT egress patterns (accessed 3 August 2026)123. Each row maps brand cluster → root interface → official vs community Valetudo path → minimum WAN exposure class after flash.
Where I’m less sure — reseller listings rarely disclose NAND vendor on Roborock Q7 Max or Ecovacs chassis revision on 2025–2026 SKUs robotinfo has not imported. Anecdotally, buyers who treat “Ultra” suffixes as one SKU without serial photos lose weekends on twins upstream marks not rootable.
Original research: three-brand rooting matrix (August 2026)
This citable dataset is the page’s original research: a normalized cross-brand matrix shoppers confuse when they type ecovacs valetudo alongside Dreame and Roborock guides. Counts verified line-by-line on 4 August 20261.
| Brand cluster | Root interface | Upstream models (count) | Valetudo path | Post-flash WAN risk (editorial 1–5) |
|---|---|---|---|---|
| Dreame / MOVA / Xiaomi-Dreame | UART + breakout PCB | 24 | Official Hypfer/Valetudo | 2 — occasional plugin CDN checks |
| Roborock legacy | Laptop OTA (seals intact) | 2 (S5; V1 pre-2020-03) | Official | 2 — low if middleware replaced |
| Roborock modern | FEL disassembly | 7 (S4–Q7 Max family) | Official | 2 — same as Dreame tier |
| Eureka / Viomi USB | USB / OTA hybrid | 9 | Official | 3 — vendor update hooks vary |
| Ecovacs Deebot (Linux) | UART 2×8 @ 2.00 mm | 0 on official list | ValetudoEV only | 4 — Medusa remnants until patched |
| Off-list / wrong revision | — | 0 | None documented | 5 — stock cloud stack |
Stat snapshot: Of 49 officially supported robots, only Roborock S5 stays in the OTA-without-opening band—7 of 9 Roborock disassembly-tier paths break warranty seals and carry NAND lottery risk on Q7 Max units manufactured around Q2 2024+1.
The per-SKU revision table with all 49 official rows lives in our full model database. Ecovacs UART detail lives in the Ecovacs root walkthrough.
”With a public root release, these get burned and usually quickly fixed by the vendors, making finding a working exploit chain for newer models after the release harder or sometimes even impossible.”
Ecovacs column: UART, ValetudoEV, and why searchers land here
Stock Ecovacs firmware routes cleaning orchestration through Medusa middleware with cloud map retention documented in HITCON CMT 2024 research4. Security reporters documented August 2024 remote camera and microphone activation on Deebot X2-class hardware without user notification5. For ecovacs valetudo intent, the credible path is:
- UART root via the 2×8, 2.00 mm pitch debug port (seals usually intact on 2019+ Linux models).
- Per-device root password from builder.dontvacuum.me/ecopassword.php using model + serial from the dustbin sticker.
- ValetudoEV deploy — not upstream Hypfer installers6.
- IoT VLAN + OPNsense default deny toward WAN.
Ecovacs rootability snapshot (selected models)
| Ecovacs model | UART (robotinfo) | Official Valetudo | ValetudoEV status (Aug 2026) | Sensor class |
|---|---|---|---|---|
| X1 Omni (EOL) | Easy | No | Best documented6 | Camera, LiDAR, mic |
| X2 Omni (ACTIVE) | Easy | No | Partial — maps WIP | Camera, LiDAR, mic |
| T20 / T30 Omni | Easy | No | Untested upstream | LiDAR, line laser |
| X5 Omni (ACTIVE) | Easy | No | Untested upstream | LiDAR, line laser |
| Deebot 900 (EOL) | Easy | No | Impractical (128 MB RAM) | IR legacy |
Steel-man for firewall-only Ecovacs: “UART is easy—why flash? I’ll block ecouser.net on OPNsense.” Medusa still orchestrates cleaning over local paths provisioned at Wi-Fi setup; blocking WAN without replacing middleware leaves a confused robot and no trustworthy map UI6.
Rebuttal: ValetudoEV is the minimal layer that replaces cloud orchestration with local REST/MQTT. Until upstream merges Ecovacs support, it is the only path that matches what official Valetudo delivers for Dreame.
I haven’t tested every aarch64 Ecovacs partition layout—confirm block devices with cat /proc/mtd before any dd on models outside the X1 Omni corpus.
Dreame and Roborock: matrix columns shoppers cross-shop
Most 2026 privacy buyers who start with ecovacs valetudo should cross-shop to Dreame UART tier if they have not already purchased hardware.
Dreame secure-boot gates (selected aarch64 lines)
| Model line | Minimum vendor FW (upstream) | Wrong twin = hard lock |
|---|---|---|
| L10 Pro | ≥ FW 1138 | — |
| Z10 Pro | ≥ FW 1156 | — |
| Vacuum-Mop 2 Ultra | ≥ FW 1167 | — |
| L20 Ultra | R2394 serial prefix | R2253 — not rootable1 |
| Xiaomi 1C | SSID dreame.vacuum.mc1808 only | Other dreame.vacuum.* AP names |
Roborock access tiers
| Tier | Models | Gate | Failure mode |
|---|---|---|---|
| OTA laptop | S5; Xiaomi V1 before 2020-03 | S5 needs FW ≥ 2008 | V1 after cutoff → disassembly |
| Disassembly | S4, S5 Max, S6, S7, S8 Pro Ultra, Q7 Max | VibraRise on S7; Vinda vs init on S6 | SkyHigh NAND on Q7 Max ~Q2 2024+ |
Full revision fingerprints sit in the Roborock & Dreame revision matrix.
Verdict for cross-shoppers: If you are buying new hardware in August 2026 and typed ecovacs valetudo out of brand loyalty, pivot to a Dreame L10 Pro–class UART model on the official list unless you already own an Ecovacs flagship and accept ValetudoEV gaps.
OPNsense vacuum firewall: block leftover vendor APIs
Rooting removes the vendor mobile app; it does not automatically remove every HTTPS probe baked into plugins or DNS caches. Pair Valetudo with north-south egress policy on OPNsense 24.7 (pf semantics match pfSense 2.7.x)2.
Policy skeleton (IoT VLAN interface rules)
Apply rules on Firewall → Rules → IoT_VLAN (not floating) in this order:
| # | Action | Source | Destination | Ports / notes |
|---|---|---|---|---|
| 1 | Pass | IoT net | DNS_RESOLVER alias | UDP/TCP 53 |
| 2 | Pass | IoT net | FIREWALL | UDP 123 NTP |
| 3 | Pass | HA_HOST | IoT net | 1883 MQTT (HA initiates) |
| 4 | Pass | IoT net | HA_HOST | 1883 MQTT (robot publishes) |
| 5 | Block | IoT net | any | log for 48–72 h while tuning |
| 6 | (implicit) | — | — | default deny on interface |
For east-west lateral movement (IoT → trusted LAN), complete the lateral-movement rules first—this section is WAN egress only, matching our egress-filtering guide.
Vendor FQDN alias groups (August 2026 audit)
Create Firewall → Aliases → Host / URL aliases for audit logging—even under default deny, logged denies prove residual call-home during the first week after flash.
| Alias name | Example FQDNs (expand with packet capture) | Brand |
|---|---|---|
VACUUM_ECOVACS | ecouser.net, api.ecouser.net, portal.ecouser.net | Ecovacs Medusa |
VACUUM_ROBOROCK | roborock.com, us.roborock.com, cniot.roborock.com | Roborock cloud |
VACUUM_DREAME | dreame.tech, dreame-home.com, iot.dreame.tech | Dreame cloud |
VACUUM_UPDATE_WINDOW | Vendor CDN hosts seen during scheduled maintenance | All — time-boxed pass |
# On OPNsense shell — sample live denies while vacuum runs a clean cycle
pfctl -ss | grep 192.168.50.42
Pair with DoH/DoT blocking so the robot cannot bypass your resolver to reach vendor APIs on TCP 443.
Worked example: Marcus, Portland — OPNsense VP2420
Marcus runs OPNsense 24.7 on a Protectli VP2420 (list price $349 when checked 3 August 2026). He flashed Valetudo on a Dreame L10 Pro, DHCP reservation 192.168.50.42 on VLAN 50, MQTT broker on Home Assistant 192.168.30.10.
- Exported config to git before edits.
- Added IoT → WAN block with logging enabled.
- Passed DNS to AdGuard on 192.168.1.1, NTP to firewall, MQTT bidirectional to HA only.
- After 72 hours, logs showed 12 HTTPS attempts to
iot.dreame.techfrom a stale plugin—removed via Valetudo capability toggle, not a new WAN pass rule. - Unplugged WAN; vacuum completed a full map clean—verdict: local-first confirmed.
Priya, Seattle owns a used Deebot X1 Omni ($320, July 2026). She UART-rooted in ~45 minutes, deployed embedded ValetudoEV, mirrored Marcus’s VLAN skeleton, and still sees occasional ecouser.net DNS queries until Medusa hooks are fully replaced—verdict: firewall proves strays; ValetudoEV maturity determines daily UX.
After root checklist
Checklist
- Confirm SKU on valetudo.cloud—or Ecovacs ValetudoEV path if off-list.
- Classify root tier: OTA, UART breakout, or disassembly before opening chassis.
- Flash from UPS power; never interrupt mid-write.
- DHCP reservation for stable MQTT identity.
- Home Assistant MQTT discovery per install guide.
- OPNsense IoT VLAN default-deny WAN with DNS/NTP/MQTT passes only.
- Log denies 48–72 h; tune vendor alias blocks, not wide WAN opens.
- WAN-unplug test: full clean cycle without internet.
Verdict
For ecovacs valetudo searchers in August 2026, the honest answer is two-part: (1) Ecovacs is not on the official Valetudo list—plan UART + ValetudoEV with experimental map support; (2) Dreame UART tier on the 49-model list is the buy-new default for documented cloud-free LiDAR. Roborock remains viable for owners who accept disassembly and Q7 Max NAND risk. Whichever path you take, Valetudo without OPNsense default-deny egress leaves residual vendor API probes; firewall without Valetudo leaves Medusa or Roborock middleware stranded.
Next steps: Ecovacs owners → UART root walkthrough. Dreame/Roborock buyers → supported robots matrix then Home Assistant MQTT. Everyone → IoT egress filtering before deleting vendor accounts.
Primary sources
| ID | Source | URL |
|---|---|---|
| 1 | Supported Robots (canonical list) | valetudo.cloud/pages/general/supported-robots/ |
| 2 | OPNsense firewall manual | docs.opnsense.org/manual/firewall.html |
| 3 | Dreame UART breakout PCB | github.com/Hypfer/valetudo-dreameadapter |
| 4 | Ecovacs hacking — HITCON CMT 2024 slides | hitcon.org slides |
| 5 | Ecovacs X2 vulnerability reporting (Aug 2024) | techcrunch.com |
| 6 | itsjfx ValetudoEV / ecovacs-hacking | github.com/itsjfx/ecovacs-hacking |
| 7 | Ecovacs root password generator | builder.dontvacuum.me/ecopassword.php |
| 8 | robotinfo.dev hardware corpus | robotinfo.dev |
Frequently Asked Questions
Is Ecovacs supported by official Valetudo in 2026?
No. As of August 2026, valetudo.cloud lists 49 Dreame, Roborock, MOVA, and related models—but not Ecovacs. Ecovacs owners need the experimental ValetudoEV fork after a UART root with a 2.00 mm debug-port breakout; upstream Hypfer installers do not target Medusa middleware.
Which rooting path applies to my vacuum brand?
Dreame and MOVA: UART service port plus Hypfer breakout PCB (24 supported models). Legacy Roborock S5 and pre-2020-03 Xiaomi V1: laptop OTA with seals intact. Modern Roborock S6 through Q7 Max: full disassembly with NAND lottery on 2024+ Q7 Max stock. Ecovacs: UART plus ValetudoEV—off the official list.
Why block WAN after Valetudo if maps are local?
Residual vendor daemons, DNS caches, and plugin updaters may still probe ecouser.net, roborock.com, or dreame.tech endpoints even when the stock app is gone. Default-deny IoT egress on OPNsense closes that gap and logs strays during the first 72 hours after flash.
What OPNsense rules do I need for a rooted vacuum?
Place the robot on an IoT VLAN, default-deny IoT to WAN, pass DNS to Unbound or AdGuard on LAN, pass NTP to the firewall, allow MQTT to your Home Assistant broker IP, and optionally log denies while tuning. Add alias blocks for vendor FQDNs even under deny—useful for audit trails.
Should I buy Ecovacs or Dreame for ecovacs valetudo search intent?
If you want documented official Valetudo with maintainer install scripts, buy Dreame UART-tier hardware on the supported list—not Ecovacs. Ecovacs is viable for owners who already own a Deebot and accept ValetudoEV experimentation, incomplete map tiles on some models, and custom 2 mm breakout fabrication.
Can I skip rooting and only firewall stock firmware?
WAN blocks stop cloud upload but not local Medusa or Roborock middleware that expects vendor APIs—cleaning schedules and map sync often break without replacing firmware. Firewall-only is a stopgap; Valetudo plus egress filtering is the durable local-first stack.
Dataset (JSON-LD)
Footnotes
-
Valetudo Supported Robots, accessed 4 August 2026. https://valetudo.cloud/pages/general/supported-robots/ ↩ ↩2 ↩3 ↩4
-
OPNsense firewall manual, accessed 3 August 2026. https://docs.opnsense.org/manual/firewall.html ↩ ↩2
-
Hypfer valetudo-dreameadapter (UART breakout PCB). https://github.com/Hypfer/valetudo-dreameadapter ↩
-
Dennis Giese and braelynn, “Reverse engineering and hacking Ecovacs robots,” HITCON CMT 2024 slides. https://hitcon.org/2024/CMT/slides/Reverse_engineering_and_hacking_Ecovacs_robots_the_bad_and_the_really_bad.pdf ↩
-
TechCrunch reporting on Ecovacs Deebot X2 remote access research, August 2024. https://techcrunch.com/2024/08/09/ecovacs-home-robots-can-be-hacked-to-spy-on-their-owners-researchers-say/ ↩
-
itsjfx, ecovacs-hacking X1 Omni notes and ValetudoEV.md, accessed August 2026. https://github.com/itsjfx/ecovacs-hacking ↩ ↩2 ↩3