PatchSiren

ECOVACS ROBOTICS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ECOVACS ROBOTICS CVE published 2026-08-10

CVE-2026-66411

The DEEBOT PRO M1 and DEEBOT PRO K1VAC robots are affected by a vulnerability in their Websocket communications, specifically in the authentication algorithm implementation. This allows unauthenticated attackers to connect and operate the affected robots. The CVE record was published on 2026-08-10T09:17:23.483Z and has not been modified since then. Users should verify their inventory and review compensating controls.

LOW ECOVACS ROBOTICS CVE published 2026-08-10

CVE-2026-66410

The ECOVACS PRO App for Android and iOS improperly validates server certificates, potentially allowing communication interception or alteration. This vulnerability has a CVSS score of 2.3 and is considered low-severity. Affected products include ECOVACS PRO App for Android and iOS. The vulnerability is related to improper validation of server certificates, which could allow attackers to intercept or alter [truncated]

MEDIUM ECOVACS ROBOTICS CVE published 2026-08-10

CVE-2026-66409

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T09:17:23.210Z and has not been modified since then. The DEEBOT PRO M1 and DEEBOT PRO K1VAC devices are configured with weak passwords for their Wi-Fi hotspot networks, potentially allowing unauthorized access. This vulnerability has a medium severity level, with a CVSS score of 6.9. Users of affe [truncated]

MEDIUM ECOVACS ROBOTICS CVE published 2026-08-10

CVE-2026-66408

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T09:17:23.060Z and has not been modified since then. The vulnerability affects DEEBOT PRO M1 and DEEBOT PRO K1VAC devices, which have root accounts configured with weak passwords. Physical access to an affected product may allow an attacker to obtain the password of the root account, potentially l [truncated]

HIGH ECOVACS ROBOTICS CVE published 2026-08-10

CVE-2026-66407

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T09:17:22.917Z and has not been modified since then. DEEBOT PRO M1 and DEEBOT PRO K1VAC devices have a vulnerability in their WebSocket communication authentication mechanism, potentially allowing man-in-the-middle attacks. This vulnerability can be exploited by analyzing traffic data, potentially [truncated]

HIGH ECOVACS ROBOTICS CVE published 2026-08-10

CVE-2026-66405

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-66405 was published on 2026-08-10T09:17:22.637Z and has not been modified since then. The vulnerability affects DEEBOT PRO M1 and DEEBOT PRO K1VAC, which leave telnet servers enabled. This may be leveraged to log in to the affected products. Organizations using these products should verify and address the telne [truncated]