CVE-2026-66405
8.8ECOVACS ROBOTICS · DEEBOT PRO M1, DEEBOT PRO K1VAC
Telnet servers are left enabled in DEEBOT PRO M1 and K1VAC devices, exposing them to potential unauthorized access by authenticated users.
Executive summary
Enabled telnet services in ECOVACS DEEBOT PRO devices create a significant risk of unauthorized access and system control.
Vulnerability
This vulnerability involves the presence of active debug code (CWE-489) in the form of an enabled telnet service. It requires an authenticated user (PR:L) to leverage the service for unauthorized interaction.
Business impact
Leaving telnet enabled provides an unnecessary attack vector that could allow an attacker with low-level credentials to gain deeper access to the device. With a CVSS score of 8.8, this represents a high-risk security oversight that could lead to full device compromise and potential integration into a botnet.
Remediation
Immediate Action: Update the DEEBOT PRO M1 to firmware version M1-1.7.27 or later, and the DEEBOT PRO K1VAC to version V1.7.821 or later.
Proactive Monitoring: Audit network traffic for any telnet (Port 23) activity originating from or directed toward these robotic devices.
Compensating Controls: Isolate these devices on a dedicated network segment with strict firewall rules that block all unsolicited inbound connections, especially those targeting administrative ports.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Owners and administrators of these ECOVACS devices must apply the provided firmware updates immediately. Disabling unnecessary services like telnet is a fundamental security practice that must be enforced to protect embedded hardware from unauthorized exploitation.