Weak Wi-Fi Password Vulnerability in DEEBOT PRO M1 and K1VAC by Ecovacs Robotics
CVE-2026-66409

6.9MEDIUM

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-66409?

The DEEBOT PRO M1 and DEEBOT PRO K1VAC by Ecovacs Robotics are susceptible to a security issue where the Wi-Fi hotspot networks are configured with weak passwords. This vulnerability allows unauthorized users to potentially analyze and obtain the weak Wi-Fi password, granting them access to the robot's network. Addressing this issue is crucial to ensure the privacy and security of users who rely on these smart cleaning devices.

Affected Version(s)

DEEBOT PRO K1VAC 0

DEEBOT PRO M1 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.