Telnet Vulnerability in DEEBOT PRO Products from Ecovacs Robotics
CVE-2026-66405

8.7HIGH

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-66405?

DEEBOT PRO M1 and DEEBOT PRO K1VAC devices from Ecovacs Robotics have the telnet service enabled, potentially allowing unauthorized access. This vulnerability arises from the lack of proper configuration, which can be exploited by attackers to gain control over the devices. Users should ensure that telnet access is disabled to mitigate risks associated with unauthorized remote login and device manipulation.

Affected Version(s)

DEEBOT PRO K1VAC 0

DEEBOT PRO M1 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.