Web Server Vulnerability in DEEBOT PRO Products by Ecovacs
CVE-2026-66403

8.7HIGH

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-66403?

Ecovacs has identified a security flaw in the DEEBOT PRO M1 and K1VAC models where the web server remains enabled for debugging. This unintended exposure allows unauthorized access to sensitive data, such as floor maps and operational logs, potentially compromising user privacy and security.

Affected Version(s)

DEEBOT PRO K1VAC 0

DEEBOT PRO M1 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.