CVE-2026-66407
Received Received - Intake

Authentication Bypass in DEEBOT PRO M1 and DEEBOT PRO K1VAC

Vulnerability report for CVE-2026-66407, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: JPCERT/CC

Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ecovacs deebot_pro_m1 *
ecovacs deebot_pro_k1vac *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

DEEBOT PRO M1 and DEEBOT PRO K1VAC devices have a flaw in their WebSocket authentication. An attacker can intercept WebSocket traffic via a man-in-the-middle attack to retrieve the private key and alter communication contents.

Detection Guidance

Detecting this vulnerability requires monitoring WebSocket traffic for improper authentication. Use network sniffing tools like Wireshark or tcpdump to capture WebSocket frames. Look for unencrypted or weakly encrypted communication between DEEBOT devices and their controllers. Analyze traffic for exposed private keys or altered messages.

Impact Analysis

This vulnerability allows attackers to eavesdrop on or manipulate communications between the device and its server. This could lead to unauthorized control of the device or exposure of sensitive data transmitted during operation.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR and HIPAA by enabling unauthorized access to personal or health-related data transmitted by the device. Compliance could be compromised due to insufficient authentication and encryption.

Mitigation Strategies

Immediately isolate affected DEEBOT devices from untrusted networks. Disable WebSocket communication if possible or restrict it to trusted networks only. Update device firmware if patches are available. Monitor network traffic for signs of man-in-the-middle attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66407. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart