CVE-2026-66409
Received Received - Intake

Weak Wi-Fi Hotspot Password in DEEBOT PRO M1 and DEEBOT PRO K1VAC

Vulnerability report for CVE-2026-66409, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: JPCERT/CC

Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ecovacs deebot_pro_m1 *
ecovacs deebot_pro_k1vac *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1391 The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

DEEBOT PRO M1 and DEEBOT PRO K1VAC robots are set up with weak default passwords for their Wi-Fi hotspot networks. Attackers can exploit this to gain unauthorized access to the robot's access point by obtaining the password.

Detection Guidance

To detect this vulnerability, scan your network for DEEBOT PRO M1 or DEEBOT PRO K1VAC devices broadcasting Wi-Fi hotspots. Check if their default passwords are weak or easily guessable. Use network scanning tools like nmap to identify these devices and verify their Wi-Fi hotspot configurations.

Impact Analysis

An attacker could connect to the robot's Wi-Fi network, potentially intercepting data transmitted between the robot and other devices or gaining control over the robot's functions.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to Wi-Fi networks via weak passwords. Unauthorized access may lead to data breaches or unauthorized data collection, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Immediately change the Wi-Fi hotspot passwords for DEEBOT PRO M1 and DEEBOT PRO K1VAC devices to strong, unique passwords. Ensure these passwords are not reused across other devices. Disable the Wi-Fi hotspot if not required for operation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66409. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart