CVE-2026-66403
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-489
- Published
- 2026-08-10
- Last modified
- 2026-08-10
Affected products
- ECOVACS ROBOTICS DEEBOT PRO M1
- ECOVACS ROBOTICS DEEBOT PRO K1VAC
Weakness type
Related vulnerabilities
- CVE-2026-6485 — UEFI BIOS embedded Shell can be used to bypass Secure Boot
- CVE-2026-77545 — A malicious actor with access to the network, low privileges and under certain conditions could...
- CVE-2026-66787 — Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082
- CVE-2026-66405 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be...
- CVE-2026-41186 — Unauthenticated Go pprof exposure in Calico debug server
- CVE-2026-65893 — Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
- CVE-2026-58378 — Allwinner TV Box TV98 ADB exposed on network
- CVE-2026-54799 — A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...