Authentication Flaw in DEEBOT PRO Smart Robots by Ecovacs
CVE-2026-66411
6.9MEDIUM
What is CVE-2026-66411?
The DEEBOT PRO M1 and DEEBOT PRO K1VAC from Ecovacs are vulnerable due to an inadequate implementation of the authentication algorithm in Websocket communications. This flaw allows unauthenticated attackers to connect and control the affected robots, posing significant security and privacy risks. Owners of these devices should take immediate action to safeguard their systems against potential unauthorized operations.
Affected Version(s)
DEEBOT PRO K1VAC 0
DEEBOT PRO M1 0
