CVE-2026-66403
7.5ECOVACS ROBOTICS · DEEBOT PRO M1, DEEBOT PRO K1VAC
A debugging web server remains enabled in certain ECOVACS DEEBOT models, potentially allowing unauthorized access to sensitive device information.
Executive summary
The unintentional exposure of a debugging web server on specific ECOVACS DEEBOT models creates a high-severity risk of unauthorized information disclosure and potential system access.
Vulnerability
This vulnerability (CWE-489) occurs because a web server used for debugging purposes is left active in production firmware. The service is accessible to unauthenticated remote attackers.
Business impact
The active debug server could allow an attacker to gain unauthorized access to the device, potentially exposing camera feeds, microphone data, or other sensitive user information. With a CVSS score of 7.5, this poses a significant privacy and security risk to users and organizations that utilize these devices in professional environments.
Remediation
Immediate Action: Update the firmware of the affected DEEBOT units to the patched versions (M1-1.7.27 or V1.7.821) as specified by the vendor.
Proactive Monitoring: Monitor network traffic for unusual connections directed at the robotic vacuum hardware, particularly on ports associated with web-based management.
Compensating Controls: Isolate IoT devices on a dedicated, restricted network segment to prevent them from being reachable from the broader corporate network or the public internet.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Owners of the affected DEEBOT models should prioritize firmware updates to close the exposed debug interface. Until updates are applied, isolating these devices from the network is strongly recommended to protect against unauthorized remote access.