CVE-2026-66407
8.1ECOVACS · DEEBOT PRO M1, DEEBOT PRO K1VAC
ECOVACS DEEBOT PRO M1 and K1VAC devices contain an authentication vulnerability in WebSocket communications due to the use of weak cryptographic algorithms.
Executive summary
Improper authentication in WebSocket communications for ECOVACS DEEBOT PRO M1 and K1VAC devices allows potential unauthorized access due to weak cryptographic implementations.
Vulnerability
The devices utilize broken or risky cryptographic algorithms (CWE-327) within their WebSocket communication protocol. This improper implementation of authentication allows an attacker to potentially compromise the communication channel.
Business impact
Exploitation of this vulnerability could allow an attacker to intercept or manipulate data transmitted between the device and the control interface. This poses risks to both user privacy and the operational integrity of the robotic devices. With a CVSS score of 8.1, the high severity justifies prompt remediation to prevent potential unauthorized command execution or data leakage.
Remediation
Immediate Action: Update the DEEBOT PRO M1 to version M1-1.7.27 or later, and the DEEBOT PRO K1VAC to version V1.7.821 or later.
Proactive Monitoring: Monitor network traffic associated with these devices for unusual WebSocket connection patterns or failed authentication attempts.
Compensating Controls: Isolate IoT devices on a separate network segment to minimize the impact of a potential compromise and prevent lateral movement.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
All administrators of ECOVACS DEEBOT units should verify their firmware versions and perform the recommended updates to address the cryptographic weakness. Maintaining up-to-date firmware is essential for securing the communication channels of these connected devices.