CVE-2026-66404

Summary

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.

Affected Software

VendorProductVersion RangeStatus
ECOVACS ROBOTICSDEEBOT PRO M10 < M1-1.7.27affected
ECOVACS ROBOTICSDEEBOT PRO K1VAC0 < V1.7.821affected

Weaknesses

  • CWE-295: Improper certificate validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References