# CVE-2026-66408

## Summary

- **CVE ID:** CVE-2026-66408
- **Severity:** MEDIUM
- **CVSS Score:** 5.1 (CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1391
- **Published:** Aug 10, 2026
- **Last Modified:** Aug 10, 2026

## Description

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may allow to obtain the password of the root account.

## Affected Products

- ECOVACS ROBOTICS — DEEBOT PRO M1 (0)
- ECOVACS ROBOTICS — DEEBOT PRO K1VAC (0)

## References

- [CNA](https://robot.hellohas.co.jp/news/update_20260331/)
- [CNA](https://jvn.jp/en/vu/JVNVU92804348/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._