CVE-2026-66411

Summary

DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot.

Affected Software

VendorProductVersion RangeStatus
ECOVACS ROBOTICSDEEBOT PRO M10 < M1-1.7.27affected
ECOVACS ROBOTICSDEEBOT PRO K1VAC0 < V1.7.821affected

Weaknesses

  • CWE-303: Incorrect Implementation of Authentication Algorithm

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References