Ecovacs
Ecovacs Deebot PRO M1: vulnerabilidades y CVE
Ecovacs Deebot PRO M1 tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66411 | Media (6.9) | 0.39% | — | 10 ago 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot. |
| CVE-2026-66409 | Media (6.9) | 0.33% | — | 10 ago 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot. |
| CVE-2026-66408 | Media (5.1) | 0.20% | — | 10 ago 2026 | The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account. |
| CVE-2026-66407 | Alta (7.7) | 0.33% | — | 10 ago 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and… |
| CVE-2026-66406 | Baja (2.3) | 0.15% | — | 10 ago 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result,… |
| CVE-2026-66405 | Alta (8.7) | 0.51% | — | 10 ago 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products. |
| CVE-2026-66404 | Media (6) | 0.20% | — | 10 ago 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved. |
| CVE-2026-66403 | Alta (8.7) | 0.43% | — | 10 ago 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.