Authentication Flaw in DEEBOT PRO Series by Ecovacs
CVE-2026-66407

7.7HIGH

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-66407?

Ecovacs' DEEBOT PRO M1 and DEEBOT PRO K1 devices exhibit a security flaw that allows an attacker to intercept and manipulate WebSocket communication. Due to improper authentication practices, attackers can retrieve the WebSocket private key through traffic analysis, potentially compromising device integrity and user privacy.

Affected Version(s)

DEEBOT PRO K1VAC 0

DEEBOT PRO M1 0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.