Server Certificate Validation Flaw in ECOVACS PRO App for Android and iOS
CVE-2026-66410

2.3LOW

What is CVE-2026-66410?

The ECOVACS PRO App for Android and iOS exhibits a serious flaw in the validation of server certificates. This vulnerability allows an attacker to intercept and manipulate communications between the app and its servers, posing significant risks to user data integrity and confidentiality. Users of the affected application should be aware of potential exposure to man-in-the-middle attacks due to this oversight in secure communication practices.

Affected Version(s)

Android App "ECOVACS PRO" 0 < 1.3.82

iOS App "ECOVACS PRO" 0 < 1.3.82

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.