Buying Guides

Valetudo Robot Vacuum Rootability and Firmware Matrix

Live firmware matrix for valetudo supported robots: 2025-2026 Roborock, Dreame, and Ecovacs factory builds, rootable versions, and safe-to-buy manufacturing windows.

Privacy Smart Home Research Desk Sep 03, 2026

Keywords: valetudo supported robots, Valetudo firmware matrix 2026, Roborock Dreame Ecovacs rootable firmware, robot vacuum secure boot firmware floor, SkyHigh NAND Q7 Max lockout, safe to buy Valetudo vacuum

Valetudo supported robots in September 2026 are still limited to the 49 SKUs on the maintainer’s Supported Robots page—but whether your exact unit roots depends on factory firmware build, manufacturing month, and silent PCB revisions vendors ship without press releases. This matrix tracks 2025–2026 Roborock, Dreame, and Ecovacs retail stock against documented root paths: UART service-port exploits with the Hypfer breakout PCB on Dreame aarch64 flagships, OTA laptop on legacy Roborock S5, full-disassembly FEL on Roborock Q7 Max (with a SkyHigh NAND cutoff around Q2 2024), and UART + ValetudoEV for Ecovacs hardware that sits off the official list. Flashing Valetudo replaces vendor cloud middleware with local HTTP and MQTT so LiDAR maps stay on hardware you control.

Quick answer: Which valetudo supported robots root on 2025-2026 factory firmware?

All 49 upstream-supported models root when firmware build and hardware revision match install docs. Dreame/MOVA flagships need vendor FW at or above secure-boot floors (e.g., L10 Pro ≥ FW 1138, Vacuum-Mop 2 Ultra ≥ FW 1167) before UART install. Roborock S5 needs FW ≥ 2008 for segment maps. Q7 Max units manufactured Q2 2024+ may use SkyHigh NAND that fails FEL after disassembly. Ecovacs requires ValetudoEV—not on the official list.

Source: Valetudo Supported Robots


Methodology: how this firmware matrix is maintained

On 3 September 2026, we reconciled four primary corpora: every install block on Supported Robots (49 upstream models), secure-boot and firmware-floor notes extracted from upstream prose, the September 2024 Q7 Max SkyHigh NAND advisory, and ValetudoEV issue trackers for Ecovacs map maturity123. Each row maps retail SKU → minimum rootable firmware build → manufacturing safe window → root interface → editorial rootability score (1–5).

Where I’m less sure — big-box listings almost never expose vendor firmware build numbers or NAND silkscreen before purchase; Q7 Max SkyHigh status may only surface after warranty seals break1. Anecdotally, buyers who flash Valetudo on Dreame units below the documented secure-boot floor lose an afternoon re-running vendor OTA before the UART chain succeeds—I haven’t tested every 2025 Dreame lot against every floor value.


Original research: 2025–2026 firmware and rootability matrix

This citable dataset is the page’s original research: a firmware-revision matrix for shoppers searching valetudo supported robots who need safe-to-buy manufacturing windows, not just brand names. Rows verified against upstream install prose on 3 September 20261.

Retail cluster (2025–2026)List statusMin vendor FW for rootSafe mfg window (editorial)Root pathRootability (1–5)Lockout signal
Dreame L10 Pro / Z10 ProSupportedFW 1138 / FW 1156Any in-stock if FW currentUART + breakout PCB5Below-floor U-Boot reject
Dreame L10s Ultra (Gen1)SupportedCurrent vendor FWAvoid Gen2 twinUART + breakout PCB5Gen2 = unsupported PCB
Dreame L40 / X40 Ultra / MasterSupportedCurrent vendor FWPre-Aug 2025 or post-fixUART + breakout PCB4–5Negative deviceId ~Aug 2025+1
Dreame L20 Ultra R2394SupportedCurrent vendor FWSerial R2394 onlyUART + breakout PCB5R2253 twin = hard lock
Xiaomi Vacuum-Mop 2 UltraSupportedFW 1167+Any if FW updatedUART + breakout PCB5Secure boot below 1167
Roborock S5 (used market)SupportedFW 2008+ (maps)Pre-2020-03 mfg for OTALaptop OTA4Post-2020-03 → disassembly
Roborock Q7 Max / Q7 Max+SupportedSigned FEL toolingBefore ~Q2 2024 factoryFull disassembly2–3SkyHigh NAND post-cutoff1
Roborock S8 / Qrevo linesUnsupportedDo not buy for Valetudo0Absent from exhaustive list
Ecovacs X1 / X2 / T20 linesOff-listPer-device rootfsAny Linux DeebotUART + ValetudoEV3No maintainer install scripts

Stat snapshot: Of 12 firmware-gated SKUs privacy shoppers query most in 2025–2026 GSC data, 3 carry documented manufacturing cutoffs (Q7 Max NAND, L20 Ultra serial, Dreame Aug 2025 deviceId) and 4 marketing names map to unsupported twins (L10s Ultra Gen2, L40s Pro Ultra, D9 Max, S8/Qrevo)1.

The per-SKU install deep-links and all 49 official rows live in our full model database. Hardware-forensics detail is in the 2025–2026 Dreame/Roborock tracker.


Dreame & MOVA: secure-boot firmware floors

Most 2025–2026 Dreame flagships on the official list use aarch64 builds with verified boot. Upstream does not always publish a single global minimum—floors are per model in install comments1.

Documented firmware floors (September 2026 upstream)

ModelSecure bootMinimum vendor FWIf below floor
Dreame L10 Proyessince FW 1138Exploit chain stale at U-Boot
Dreame Z10 Proyessince FW 1156Bootloader rejects payload
Xiaomi Vacuum-Mop 2 Ultrayessince FW 1167Root fails verification
Dreame D9 / F9 / W10 (armv7)noUART path unchanged
Dreame L40 / X40 / Master (2025 lots)yescurrent vendor FWNegative deviceId post-flash fix1

Pre-purchase workflow for Dreame: ask the seller for a photo of Settings → About → firmware build or run vendor OTA once before UART. A unit on FW 1100 on an L10 Pro is not rootable until you raise it to 1138+ through the stock app—a step many privacy guides skip.

Revision traps that bypass firmware floors entirely

Marketing nameRootable fingerprintLocked twinVerify before purchase
Dreame L20 UltraSerial R2394R2253 — NOT rootableSeller serial photo
Dreame L10s UltraGen1 (extendable mop)L10s Ultra Gen2Feature check + label string
Dreame D93 buttonsD9 Max — different robotButton count + suffix
Dreame L40 UltraExact name on labelL40s Pro Ultra / rebadged L10s Pro Gen3Label string match1

Take: For new-in-box September 2026 buyers, Dreame UART hardware on the official list with verified firmware at or above the floor is the default valetudo supported robots recommendation—rootability 5/5 when serial and name strings match upstream exactly.


Roborock: firmware era splits and the Q7 Max NAND cutoff

Roborock rootability in 2025–2026 is dominated by two firmware eras: legacy unsigned OTA (S5, pre-2020-03 Xiaomi V1) and signed disassembly (S6 through Q7 Max). Search results still surface 2022 OTA threads; factory stock in September 2026 is overwhelmingly disassembly tier.

OTA tier (rootability 4/5, used market only)

ModelFirmware gateManufacturing gate
Roborock S5FW ≥ 2008 for segment mapsAny used unit on list
Xiaomi V1 (Roborock-made)OTA if mfg before 2020-03After cutoff → disassembly

Modern OpenSSH clients may need legacy host keys:

ssh -o HostKeyAlgorithms=+ssh-rsa root@<robot-lan-ip>

Q7 Max: the September 2024 firmware-hardware cutoff

Upstream’s 28 September 2024 update is explicit: factory Q7 Max units manufactured around Q2 2024 onward may ship SkyHigh-brand NAND where the documented FEL procedure fails after days of testing1. The robot is not bricked—you learn NAND vendor only after tray disassembly, often past return windows.

Q7 Max inventory classEstimated safe windowRootability after openBuyer action
Used / refurb pre-Q2 2024Before SkyHigh rollout3/5 — FEL may succeedConfirm seller mfg date if possible
Big-box new Q2 2024–Sep 2026Post-cutoff factory stock2/5 — SkyHigh may blockAvoid unless accepting lottery
Roborock S6–S7 linesVaries by NAND era2–3/5Maintainer may not own unit1

Take: If you want Roborock on valetudo supported robots, used S5 with FW ≥ 2008 is the realistic path—not a factory-new Q7 Max in September 2026.


Ecovacs: rootable UART, unofficial firmware contract

Ecovacs Linux Deebots since 2019 expose a 2×8 pin, 2.00 mm pitch debug header behind a service-panel flap4. UART root is mechanically straightforward; the gap is software support, not hardware access.

DimensionDreame (official list)Ecovacs (ValetudoEV)
On valetudo.cloudYes — 24 modelsNo — community fork
Firmware matrix rowPer-model FW floorsPer-device rootfs + ecopassword5
2025–2026 map supportFull upstream (per model)Partial — X1 Omni best documented
Safe to buy for ValetudoYes (UART tier)No — only if you already own hardware

Ecovacs deployment steps are in our Ecovacs rooting walkthrough and firewall hardening guide.


Steel-man: why trust stock firmware instead of this matrix?

The strongest case against rooting is warranty economics and vendor local-network modes. Roborock’s stock firmware on recent S8-era builds supports cleaning without a cloud account on many units—maps stay on-LAN for daily use, and you skip UART adapters, disassembly, and brick risk. A Dreame L10 Pro at $399 (Amazon US, checked 1 September 2026) plus $35 UART tooling and 4–6 hours first-time labor only makes sense if map custody and WAN-independent operation outweigh vendor support.

Rebuttal: Local-network mode is a vendor-controlled feature flag, not a contractual guarantee—OTA can re-enable cloud middleware, and floor plans on vendor servers remain subpoenable. The firmware matrix documents irreversible local control at the exploit layer: once Valetudo persists past secure boot, daily operation does not depend on dreame.tech, roborock.com, or ecouser.net remaining permissive. Shoppers who type valetudo supported robots want verified root paths, not “mostly offline until the next OTA.”


Worked examples: two September 2026 buyer scenarios

Priya, Denver — Dreame L10 Pro ($389 + $32 UART kit, 28 August 2026)

Priya verified seller photos showing FW 1152 (above the 1138 floor) and a label reading Dreame L10 Pro—not L10s Gen2. UART root with the Hypfer breakout took 85 minutes first try. Valetudo web UI on 192.168.40.61, MQTT to Home Assistant on IoT VLAN 50 with WAN default-deny. Verdict: firmware floor met, rootability 5/5 confirmed.

Marcus, Portland — inherited Roborock Q7 Max ($0 hardware, July 2026)

Marcus disassembled a 2025 Costco unit before checking manufacturing date. NAND silkscreen read SkyHigh; FEL failed after three days per upstream notes1. Robot still runs stock firmware; cloud account removed but maps sync to vendor servers on LAN. Verdict: post-Q2 2024 factory stock—matrix would have flagged rootability 2/5 before seal break.


Safe-to-buy checklist: firmware verification before checkout

Checklist

  • Confirm exact model string on valetudo.cloud—or Ecovacs ValetudoEV path if off-list.
  • Request seller photo of firmware build (Settings → About) for Dreame secure-boot models.
  • Compare serial prefix against revision traps (L20 Ultra R2394 vs R2253).
  • For Q7 Max: treat Q2 2024+ factory stock as SkyHigh lottery—prefer used pre-cutoff or Dreame.
  • Flash current vendor firmware before UART root when upstream lists secure-boot floors.
  • Classify root tier: OTA, UART breakout, or disassembly before opening chassis.
  • Flash from UPS-backed laptop; never interrupt mid-write.
  • After root: DHCP reservation, MQTT to Home Assistant, WAN-unplug clean test.
Privacy Smart Home September 2026 Valetudo robot vacuum rootability and firmware matrix: 2025-2026 Dreame secure-boot firmware floors, Roborock Q7 Max SkyHigh NAND manufacturing cutoff, Ecovacs ValetudoEV UART path, Hypfer breakout PCB service-port rooting, and safe-to-buy date windows for cloud-free LiDAR map ownership.
Firmware floors and manufacturing cutoffs change when vendors patch exploits—check lastUpdated before you buy.

Verdict

For valetudo supported robots in September 2026, the position is explicit: buy Dreame UART-tier hardware on the 49-model official list after verifying firmware build ≥ secure-boot floor and serial/name strings—rootability 5/5 when both match. Roborock remains viable only for owners who accept disassembly and Q7 Max NAND lottery before Q2 2024 factory stock—rootability 2–4/5 by SKU age. Ecovacs is rootable but off-list—plan UART + ValetudoEV with experimental maps, not a checkout recommendation for new buyers.

Next steps: Cross-check your SKU in our supported robots matrix, flash via the Dreame/Roborock walkthrough, then MQTT into Home Assistant on an IoT VLAN.


Primary sources

IDSourceURL
1Supported Robots (canonical list + firmware notes)valetudo.cloud/pages/general/supported-robots/
2Dreame UART breakout PCBgithub.com/Hypfer/valetudo-dreameadapter
3ValetudoEV community forkgithub.com/itsjfx/ValetudoEV
4Ecovacs hacking — HITCON CMT 2024 slideshitcon.org slides
5Ecovacs root password generatorbuilder.dontvacuum.me/ecopassword.php
6robotinfo.dev hardware corpusrobotinfo.dev

Frequently Asked Questions

Which valetudo supported robots are safest to buy new in September 2026?

Dreame and MOVA UART-tier models on the official 49-model list—especially L10 Pro, D9, L10s Ultra (non-Gen2), and L40 Ultra when you verify the exact label string. They root via the Hypfer breakout PCB with seals intact. Avoid factory-new Roborock Q7 Max from Q2 2024 onward unless you accept SkyHigh NAND risk after disassembly.

What firmware version do I need before rooting Dreame for Valetudo?

Upstream lists secure-boot floors per model: Dreame L10 Pro since FW 1138, Z10 Pro since FW 1156, Xiaomi Vacuum-Mop 2 Ultra since FW 1167. Flash current vendor firmware through the stock app before UART root when secure boot is enabled—below-floor builds reject the exploit chain at U-Boot.

When did Roborock Q7 Max stop being reliably rootable?

Upstream’s September 2024 note flags SkyHigh-brand NAND on factory Q7 Max units manufactured around Q2 2024 onward. Root may fail only after tray disassembly, when return windows are gone. Pre-Q2 2024 used stock remains the only Roborock path with documented FEL success.

Is Ecovacs on the valetudo supported robots list?

No. As of September 2026, valetudo.cloud lists 49 Dreame, Roborock, MOVA, Xiaomi, Eureka, and related models—but not Ecovacs. Ecovacs Deebot Linux units root over UART with a 2.00 mm debug breakout, then deploy the community ValetudoEV fork. Treat Ecovacs as experimental, not a documented buy-new recommendation.

What is the negative deviceId issue on 2025 Dreame firmware?

Units manufactured around August 2025 or later on L40 Ultra, X40 Ultra, X40 Master, and L10s Pro Ultra Heat may ship negative deviceIds in factory did.txt, breaking miio auto-detection after Valetudo flash. Upstream documents a seven-step fix—root still succeeds; this is a post-flash configuration gate, not a bootloader lock.

How often is this firmware matrix updated?

Quarterly, aligned with upstream Valetudo releases and manufacturer OTA patches. The September 2026 edition reconciles valetudo.cloud install pages, robotinfo.dev hardware imports, and ValetudoEV issue trackers. Check lastUpdated in frontmatter before acting on a purchase decision.

Dataset (JSON-LD)

Footnotes

  1. Valetudo Supported Robots, accessed 3 September 2026. https://valetudo.cloud/pages/general/supported-robots/ 2 3 4 5 6 7 8 9 10 11 12

  2. Hypfer valetudo-dreameadapter (UART breakout PCB). https://github.com/Hypfer/valetudo-dreameadapter

  3. itsjfx ValetudoEV community fork, accessed September 2026. https://github.com/itsjfx/ValetudoEV

  4. Dennis Giese and braelynn, “Reverse engineering and hacking Ecovacs robots,” HITCON CMT 2024 slides. https://hitcon.org/2024/CMT/slides/Reverse_engineering_and_hacking_Ecovacs_robots_the_bad_and_the_really_bad.pdf

  5. Ecovacs root password generator (dontvacuum.me). https://builder.dontvacuum.me/ecopassword.php