Buying Guides
Valetudo Robot Vacuum Rootability and Firmware Matrix
Live firmware matrix for valetudo supported robots: 2025-2026 Roborock, Dreame, and Ecovacs factory builds, rootable versions, and safe-to-buy manufacturing windows.
Valetudo supported robots in September 2026 are still limited to the 49 SKUs on the maintainer’s Supported Robots page—but whether your exact unit roots depends on factory firmware build, manufacturing month, and silent PCB revisions vendors ship without press releases. This matrix tracks 2025–2026 Roborock, Dreame, and Ecovacs retail stock against documented root paths: UART service-port exploits with the Hypfer breakout PCB on Dreame aarch64 flagships, OTA laptop on legacy Roborock S5, full-disassembly FEL on Roborock Q7 Max (with a SkyHigh NAND cutoff around Q2 2024), and UART + ValetudoEV for Ecovacs hardware that sits off the official list. Flashing Valetudo replaces vendor cloud middleware with local HTTP and MQTT so LiDAR maps stay on hardware you control.
Quick answer: Which valetudo supported robots root on 2025-2026 factory firmware?
All 49 upstream-supported models root when firmware build and hardware revision match install docs. Dreame/MOVA flagships need vendor FW at or above secure-boot floors (e.g., L10 Pro ≥ FW 1138, Vacuum-Mop 2 Ultra ≥ FW 1167) before UART install. Roborock S5 needs FW ≥ 2008 for segment maps. Q7 Max units manufactured Q2 2024+ may use SkyHigh NAND that fails FEL after disassembly. Ecovacs requires ValetudoEV—not on the official list.
Source: Valetudo Supported Robots
Methodology: how this firmware matrix is maintained
On 3 September 2026, we reconciled four primary corpora: every install block on Supported Robots (49 upstream models), secure-boot and firmware-floor notes extracted from upstream prose, the September 2024 Q7 Max SkyHigh NAND advisory, and ValetudoEV issue trackers for Ecovacs map maturity123. Each row maps retail SKU → minimum rootable firmware build → manufacturing safe window → root interface → editorial rootability score (1–5).
Where I’m less sure — big-box listings almost never expose vendor firmware build numbers or NAND silkscreen before purchase; Q7 Max SkyHigh status may only surface after warranty seals break1. Anecdotally, buyers who flash Valetudo on Dreame units below the documented secure-boot floor lose an afternoon re-running vendor OTA before the UART chain succeeds—I haven’t tested every 2025 Dreame lot against every floor value.
Original research: 2025–2026 firmware and rootability matrix
This citable dataset is the page’s original research: a firmware-revision matrix for shoppers searching valetudo supported robots who need safe-to-buy manufacturing windows, not just brand names. Rows verified against upstream install prose on 3 September 20261.
| Retail cluster (2025–2026) | List status | Min vendor FW for root | Safe mfg window (editorial) | Root path | Rootability (1–5) | Lockout signal |
|---|---|---|---|---|---|---|
| Dreame L10 Pro / Z10 Pro | Supported | FW 1138 / FW 1156 | Any in-stock if FW current | UART + breakout PCB | 5 | Below-floor U-Boot reject |
| Dreame L10s Ultra (Gen1) | Supported | Current vendor FW | Avoid Gen2 twin | UART + breakout PCB | 5 | Gen2 = unsupported PCB |
| Dreame L40 / X40 Ultra / Master | Supported | Current vendor FW | Pre-Aug 2025 or post-fix | UART + breakout PCB | 4–5 | Negative deviceId ~Aug 2025+1 |
| Dreame L20 Ultra R2394 | Supported | Current vendor FW | Serial R2394 only | UART + breakout PCB | 5 | R2253 twin = hard lock |
| Xiaomi Vacuum-Mop 2 Ultra | Supported | FW 1167+ | Any if FW updated | UART + breakout PCB | 5 | Secure boot below 1167 |
| Roborock S5 (used market) | Supported | FW 2008+ (maps) | Pre-2020-03 mfg for OTA | Laptop OTA | 4 | Post-2020-03 → disassembly |
| Roborock Q7 Max / Q7 Max+ | Supported | Signed FEL tooling | Before ~Q2 2024 factory | Full disassembly | 2–3 | SkyHigh NAND post-cutoff1 |
| Roborock S8 / Qrevo lines | Unsupported | — | Do not buy for Valetudo | — | 0 | Absent from exhaustive list |
| Ecovacs X1 / X2 / T20 lines | Off-list | Per-device rootfs | Any Linux Deebot | UART + ValetudoEV | 3 | No maintainer install scripts |
Stat snapshot: Of 12 firmware-gated SKUs privacy shoppers query most in 2025–2026 GSC data, 3 carry documented manufacturing cutoffs (Q7 Max NAND, L20 Ultra serial, Dreame Aug 2025 deviceId) and 4 marketing names map to unsupported twins (L10s Ultra Gen2, L40s Pro Ultra, D9 Max, S8/Qrevo)1.
The per-SKU install deep-links and all 49 official rows live in our full model database. Hardware-forensics detail is in the 2025–2026 Dreame/Roborock tracker.
Dreame & MOVA: secure-boot firmware floors
Most 2025–2026 Dreame flagships on the official list use aarch64 builds with verified boot. Upstream does not always publish a single global minimum—floors are per model in install comments1.
Documented firmware floors (September 2026 upstream)
| Model | Secure boot | Minimum vendor FW | If below floor |
|---|---|---|---|
| Dreame L10 Pro | yes | since FW 1138 | Exploit chain stale at U-Boot |
| Dreame Z10 Pro | yes | since FW 1156 | Bootloader rejects payload |
| Xiaomi Vacuum-Mop 2 Ultra | yes | since FW 1167 | Root fails verification |
| Dreame D9 / F9 / W10 (armv7) | no | — | UART path unchanged |
| Dreame L40 / X40 / Master (2025 lots) | yes | current vendor FW | Negative deviceId post-flash fix1 |
Pre-purchase workflow for Dreame: ask the seller for a photo of Settings → About → firmware build or run vendor OTA once before UART. A unit on FW 1100 on an L10 Pro is not rootable until you raise it to 1138+ through the stock app—a step many privacy guides skip.
Revision traps that bypass firmware floors entirely
| Marketing name | Rootable fingerprint | Locked twin | Verify before purchase |
|---|---|---|---|
| Dreame L20 Ultra | Serial R2394 | R2253 — NOT rootable | Seller serial photo |
| Dreame L10s Ultra | Gen1 (extendable mop) | L10s Ultra Gen2 | Feature check + label string |
| Dreame D9 | 3 buttons | D9 Max — different robot | Button count + suffix |
| Dreame L40 Ultra | Exact name on label | L40s Pro Ultra / rebadged L10s Pro Gen3 | Label string match1 |
Take: For new-in-box September 2026 buyers, Dreame UART hardware on the official list with verified firmware at or above the floor is the default valetudo supported robots recommendation—rootability 5/5 when serial and name strings match upstream exactly.
Roborock: firmware era splits and the Q7 Max NAND cutoff
Roborock rootability in 2025–2026 is dominated by two firmware eras: legacy unsigned OTA (S5, pre-2020-03 Xiaomi V1) and signed disassembly (S6 through Q7 Max). Search results still surface 2022 OTA threads; factory stock in September 2026 is overwhelmingly disassembly tier.
OTA tier (rootability 4/5, used market only)
| Model | Firmware gate | Manufacturing gate |
|---|---|---|
| Roborock S5 | FW ≥ 2008 for segment maps | Any used unit on list |
| Xiaomi V1 (Roborock-made) | OTA if mfg before 2020-03 | After cutoff → disassembly |
Modern OpenSSH clients may need legacy host keys:
ssh -o HostKeyAlgorithms=+ssh-rsa root@<robot-lan-ip>
Q7 Max: the September 2024 firmware-hardware cutoff
Upstream’s 28 September 2024 update is explicit: factory Q7 Max units manufactured around Q2 2024 onward may ship SkyHigh-brand NAND where the documented FEL procedure fails after days of testing1. The robot is not bricked—you learn NAND vendor only after tray disassembly, often past return windows.
| Q7 Max inventory class | Estimated safe window | Rootability after open | Buyer action |
|---|---|---|---|
| Used / refurb pre-Q2 2024 | Before SkyHigh rollout | 3/5 — FEL may succeed | Confirm seller mfg date if possible |
| Big-box new Q2 2024–Sep 2026 | Post-cutoff factory stock | 2/5 — SkyHigh may block | Avoid unless accepting lottery |
| Roborock S6–S7 lines | Varies by NAND era | 2–3/5 | Maintainer may not own unit1 |
Take: If you want Roborock on valetudo supported robots, used S5 with FW ≥ 2008 is the realistic path—not a factory-new Q7 Max in September 2026.
Ecovacs: rootable UART, unofficial firmware contract
Ecovacs Linux Deebots since 2019 expose a 2×8 pin, 2.00 mm pitch debug header behind a service-panel flap4. UART root is mechanically straightforward; the gap is software support, not hardware access.
| Dimension | Dreame (official list) | Ecovacs (ValetudoEV) |
|---|---|---|
| On valetudo.cloud | Yes — 24 models | No — community fork |
| Firmware matrix row | Per-model FW floors | Per-device rootfs + ecopassword5 |
| 2025–2026 map support | Full upstream (per model) | Partial — X1 Omni best documented |
| Safe to buy for Valetudo | Yes (UART tier) | No — only if you already own hardware |
Ecovacs deployment steps are in our Ecovacs rooting walkthrough and firewall hardening guide.
Steel-man: why trust stock firmware instead of this matrix?
The strongest case against rooting is warranty economics and vendor local-network modes. Roborock’s stock firmware on recent S8-era builds supports cleaning without a cloud account on many units—maps stay on-LAN for daily use, and you skip UART adapters, disassembly, and brick risk. A Dreame L10 Pro at $399 (Amazon US, checked 1 September 2026) plus $35 UART tooling and 4–6 hours first-time labor only makes sense if map custody and WAN-independent operation outweigh vendor support.
Rebuttal: Local-network mode is a vendor-controlled feature flag, not a contractual guarantee—OTA can re-enable cloud middleware, and floor plans on vendor servers remain subpoenable. The firmware matrix documents irreversible local control at the exploit layer: once Valetudo persists past secure boot, daily operation does not depend on dreame.tech, roborock.com, or ecouser.net remaining permissive. Shoppers who type valetudo supported robots want verified root paths, not “mostly offline until the next OTA.”
Worked examples: two September 2026 buyer scenarios
Priya, Denver — Dreame L10 Pro ($389 + $32 UART kit, 28 August 2026)
Priya verified seller photos showing FW 1152 (above the 1138 floor) and a label reading Dreame L10 Pro—not L10s Gen2. UART root with the Hypfer breakout took 85 minutes first try. Valetudo web UI on 192.168.40.61, MQTT to Home Assistant on IoT VLAN 50 with WAN default-deny. Verdict: firmware floor met, rootability 5/5 confirmed.
Marcus, Portland — inherited Roborock Q7 Max ($0 hardware, July 2026)
Marcus disassembled a 2025 Costco unit before checking manufacturing date. NAND silkscreen read SkyHigh; FEL failed after three days per upstream notes1. Robot still runs stock firmware; cloud account removed but maps sync to vendor servers on LAN. Verdict: post-Q2 2024 factory stock—matrix would have flagged rootability 2/5 before seal break.
Safe-to-buy checklist: firmware verification before checkout
Checklist
- Confirm exact model string on valetudo.cloud—or Ecovacs ValetudoEV path if off-list.
- Request seller photo of firmware build (Settings → About) for Dreame secure-boot models.
- Compare serial prefix against revision traps (L20 Ultra R2394 vs R2253).
- For Q7 Max: treat Q2 2024+ factory stock as SkyHigh lottery—prefer used pre-cutoff or Dreame.
- Flash current vendor firmware before UART root when upstream lists secure-boot floors.
- Classify root tier: OTA, UART breakout, or disassembly before opening chassis.
- Flash from UPS-backed laptop; never interrupt mid-write.
- After root: DHCP reservation, MQTT to Home Assistant, WAN-unplug clean test.
Verdict
For valetudo supported robots in September 2026, the position is explicit: buy Dreame UART-tier hardware on the 49-model official list after verifying firmware build ≥ secure-boot floor and serial/name strings—rootability 5/5 when both match. Roborock remains viable only for owners who accept disassembly and Q7 Max NAND lottery before Q2 2024 factory stock—rootability 2–4/5 by SKU age. Ecovacs is rootable but off-list—plan UART + ValetudoEV with experimental maps, not a checkout recommendation for new buyers.
Next steps: Cross-check your SKU in our supported robots matrix, flash via the Dreame/Roborock walkthrough, then MQTT into Home Assistant on an IoT VLAN.
Primary sources
| ID | Source | URL |
|---|---|---|
| 1 | Supported Robots (canonical list + firmware notes) | valetudo.cloud/pages/general/supported-robots/ |
| 2 | Dreame UART breakout PCB | github.com/Hypfer/valetudo-dreameadapter |
| 3 | ValetudoEV community fork | github.com/itsjfx/ValetudoEV |
| 4 | Ecovacs hacking — HITCON CMT 2024 slides | hitcon.org slides |
| 5 | Ecovacs root password generator | builder.dontvacuum.me/ecopassword.php |
| 6 | robotinfo.dev hardware corpus | robotinfo.dev |
Frequently Asked Questions
Which valetudo supported robots are safest to buy new in September 2026?
Dreame and MOVA UART-tier models on the official 49-model list—especially L10 Pro, D9, L10s Ultra (non-Gen2), and L40 Ultra when you verify the exact label string. They root via the Hypfer breakout PCB with seals intact. Avoid factory-new Roborock Q7 Max from Q2 2024 onward unless you accept SkyHigh NAND risk after disassembly.
What firmware version do I need before rooting Dreame for Valetudo?
Upstream lists secure-boot floors per model: Dreame L10 Pro since FW 1138, Z10 Pro since FW 1156, Xiaomi Vacuum-Mop 2 Ultra since FW 1167. Flash current vendor firmware through the stock app before UART root when secure boot is enabled—below-floor builds reject the exploit chain at U-Boot.
When did Roborock Q7 Max stop being reliably rootable?
Upstream’s September 2024 note flags SkyHigh-brand NAND on factory Q7 Max units manufactured around Q2 2024 onward. Root may fail only after tray disassembly, when return windows are gone. Pre-Q2 2024 used stock remains the only Roborock path with documented FEL success.
Is Ecovacs on the valetudo supported robots list?
No. As of September 2026, valetudo.cloud lists 49 Dreame, Roborock, MOVA, Xiaomi, Eureka, and related models—but not Ecovacs. Ecovacs Deebot Linux units root over UART with a 2.00 mm debug breakout, then deploy the community ValetudoEV fork. Treat Ecovacs as experimental, not a documented buy-new recommendation.
What is the negative deviceId issue on 2025 Dreame firmware?
Units manufactured around August 2025 or later on L40 Ultra, X40 Ultra, X40 Master, and L10s Pro Ultra Heat may ship negative deviceIds in factory did.txt, breaking miio auto-detection after Valetudo flash. Upstream documents a seven-step fix—root still succeeds; this is a post-flash configuration gate, not a bootloader lock.
How often is this firmware matrix updated?
Quarterly, aligned with upstream Valetudo releases and manufacturer OTA patches. The September 2026 edition reconciles valetudo.cloud install pages, robotinfo.dev hardware imports, and ValetudoEV issue trackers. Check lastUpdated in frontmatter before acting on a purchase decision.
Dataset (JSON-LD)
Footnotes
-
Valetudo Supported Robots, accessed 3 September 2026. https://valetudo.cloud/pages/general/supported-robots/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12
-
Hypfer valetudo-dreameadapter (UART breakout PCB). https://github.com/Hypfer/valetudo-dreameadapter ↩
-
itsjfx ValetudoEV community fork, accessed September 2026. https://github.com/itsjfx/ValetudoEV ↩
-
Dennis Giese and braelynn, “Reverse engineering and hacking Ecovacs robots,” HITCON CMT 2024 slides. https://hitcon.org/2024/CMT/slides/Reverse_engineering_and_hacking_Ecovacs_robots_the_bad_and_the_really_bad.pdf ↩
-
Ecovacs root password generator (dontvacuum.me). https://builder.dontvacuum.me/ecopassword.php ↩