CVE-2026-66405
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-489
- Published
- 2026-08-10
- Last modified
- 2026-08-10
Affected products
- ECOVACS ROBOTICS DEEBOT PRO M1
- ECOVACS ROBOTICS DEEBOT PRO K1VAC
Weakness type
Related vulnerabilities
- CVE-2026-6485 — UEFI BIOS embedded Shell can be used to bypass Secure Boot
- CVE-2026-77545 — A malicious actor with access to the network, low privileges and under certain conditions could...
- CVE-2026-66787 — Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082
- CVE-2026-66403 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor...
- CVE-2026-41186 — Unauthenticated Go pprof exposure in Calico debug server
- CVE-2026-65893 — Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
- CVE-2026-58378 — Allwinner TV Box TV98 ADB exposed on network
- CVE-2026-54799 — A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...