CVE-2026-66407

Summary

DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.

Affected Software

VendorProductVersion RangeStatus
ECOVACS ROBOTICSDEEBOT PRO M10 < M1-1.7.27affected
ECOVACS ROBOTICSDEEBOT PRO K1VAC0 < V1.7.821affected

Weaknesses

  • CWE-327: Use of a broken or risky cryptographic algorithm

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References