Authentication Flaw in DEEBOT PRO Smart Robots by Ecovacs
CVE-2026-66411

6.9MEDIUM

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-66411?

The DEEBOT PRO M1 and DEEBOT PRO K1VAC from Ecovacs are vulnerable due to an inadequate implementation of the authentication algorithm in Websocket communications. This flaw allows unauthenticated attackers to connect and control the affected robots, posing significant security and privacy risks. Owners of these devices should take immediate action to safeguard their systems against potential unauthorized operations.

Affected Version(s)

DEEBOT PRO K1VAC 0

DEEBOT PRO M1 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.