CVE-2026-66408
Received Received - Intake

Weak Default Root Password in DEEBOT PRO M1 and DEEBOT PRO K1VAC

Vulnerability report for CVE-2026-66408, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: JPCERT/CC

Description

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ecovacs deebot_pro_m1 *
ecovacs deebot_pro_k1vac *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1391 The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability involves DEEBOT PRO M1 and DEEBOT PRO K1VAC devices having root accounts configured with weak passwords. Physical access to these devices could allow an attacker to obtain the root account password.

Detection Guidance

Physical access to the DEEBOT PRO M1 or DEEBOT PRO K1VAC devices is required to detect this vulnerability. Check if the root account has a weak password by attempting to log in with default or common credentials.

Impact Analysis

If you own or use these DEEBOT devices, an attacker with physical access could gain full control over the device by exploiting the weak root password. This could lead to unauthorized access, data theft, or misuse of the device.

Compliance Impact

This vulnerability may violate compliance requirements that mandate strong authentication and access controls, such as GDPR (data protection) and HIPAA (healthcare data security). Weak passwords could lead to unauthorized access, resulting in potential non-compliance penalties.

Mitigation Strategies

Change the root account password on DEEBOT PRO M1 and DEEBOT PRO K1VAC devices to a strong, unique password. Restrict physical access to these devices to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66408. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart