SB2026080386 - Multiple vulnerabilities in ECOVACS DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App



SB2026080386 - Multiple vulnerabilities in ECOVACS DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App

Published: August 3, 2026

Security Bulletin ID SB2026080386
CSH Severity
High
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 30% Medium 60% Low 10%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Active Debug Code (CVE-ID: CVE-2026-66403)

CWE-ID: CWE-489 - Active Debug Code

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to web server for debugging purposes remains enabled. A remote attacker can retrieve floor map and log information.


2) Improper Certificate Validation (CVE-ID: CVE-2026-66410)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper server certificate verification in the smartphone app. A remote attacker can obtain and/or alter communications of the product.


3) Improper Certificate Validation (CVE-ID: CVE-2026-66404)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to missing server certificate verification in MQTT communications. A remote attacker can retrieve operation logs and activity logs stored on the target product.


4) Active Debug Code (CVE-ID: CVE-2026-66405)

CWE-ID: CWE-489 - Active Debug Code

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to telnet server remains enabled. A remote attacker can gain access to the system.


5) Improper Certificate Validation (CVE-ID: CVE-2026-66406)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to missing server certificate verification in wget command. A remote attacker can execute arbitrary code with elevated privileges.


6) Use of a broken or risky cryptographic algorithm (CVE-ID: CVE-2026-66407)

CWE-ID: CWE-327 - Use of a Broken or Risky Cryptographic Algorithm

CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to use of a broken or risky cryptographic algorithm in WebSocket communication authentication. A remote attacker can obtain and/or alter communications of the product.


7) Use of Weak Credentials (CVE-ID: CVE-2026-66408)

CWE-ID: CWE-1391 - Use of Weak Credentials

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to weak password for root account. An attacker with physical access can obtain product's root password.


8) Use of Weak Credentials (CVE-ID: CVE-2026-66409)

CWE-ID: CWE-1391 - Use of Weak Credentials

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to weak password for Wi-Fi hotspot network. A remote attacker can analyze and obtain the hotspot password and connect to the robot's access point.


9) Dependency on vulnerable third-party component (CVE-ID: CVE-2021-31698)

CWE-ID: CWE-1395 - Dependency on Vulnerable Third-Party Component

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to dependency on vulnerable third-party component. A remote attacker can execute arbitrary code on the system.


10) Incorrect Implementation of Authentication Algorithm (CVE-ID: CVE-2026-66411)

CWE-ID: CWE-303 - Incorrect Implementation of Authentication Algorithm

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to incorrect implementation of authentication algorithm in Websocket communications. A remote attacker can connect without authentication and operate the affected robot.


Remediation

Install update from vendor's website.