CVE-2026-66405
Received Received - Intake

Telnet Service Enabled in DEEBOT PRO M1 and DEEBOT PRO K1VAC

Vulnerability report for CVE-2026-66405, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: JPCERT/CC

Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ecovacs deebot_pro_m1 *
ecovacs deebot_pro_k1vac *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-489 The product is released with debugging code still enabled or active.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The DEEBOT PRO M1 and DEEBOT PRO K1VAC devices have telnet servers enabled by default. This allows remote access to the devices without authentication, potentially letting attackers log in and take control.

Detection Guidance

Check if telnet is running on the affected DEEBOT devices by scanning for open port 23. Use commands like 'nmap -p 23 <device_IP>' or 'telnet <device_IP> 23' to verify if the telnet service is accessible.

Impact Analysis

An attacker could exploit this to gain unauthorized access to your DEEBOT device. This might allow them to monitor your home, disable security features, or use the device for further attacks on your network.

Compliance Impact

The vulnerability allows unauthorized access via enabled telnet servers, which could lead to data breaches or unauthorized control of devices. This may violate compliance requirements under GDPR (data protection) and HIPAA (health data security) by exposing sensitive information or device control.

Mitigation Strategies

Disable the telnet service on DEEBOT PRO M1 and DEEBOT PRO K1VAC devices immediately. If possible, update the firmware to a version that disables telnet by default. Block external access to port 23 via firewall rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66405. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart