The DEEBOT PRO M1 and DEEBOT PRO K1VAC robots are affected by a vulnerability in their Websocket communications, specifically in the authentication algorithm implementation. This allows unauthenticated attackers to connect and operate the affected robots. The CVE record was published on 2026-08-10T09:17:23.483Z and has not been modified since then. Users should verify their inventory and review compensating controls.
The ECOVACS PRO App for Android and iOS improperly validates server certificates, potentially allowing communication interception or alteration. This vulnerability has a CVSS score of 2.3 and is considered low-severity. Affected products include ECOVACS PRO App for Android and iOS. The vulnerability is related to improper validation of server certificates, which could allow attackers to intercept or alter [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T09:17:23.210Z and has not been modified since then. The DEEBOT PRO M1 and DEEBOT PRO K1VAC devices are configured with weak passwords for their Wi-Fi hotspot networks, potentially allowing unauthorized access. This vulnerability has a medium severity level, with a CVSS score of 6.9. Users of affe [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T09:17:23.060Z and has not been modified since then. The vulnerability affects DEEBOT PRO M1 and DEEBOT PRO K1VAC devices, which have root accounts configured with weak passwords. Physical access to an affected product may allow an attacker to obtain the password of the root account, potentially l [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T09:17:22.917Z and has not been modified since then. DEEBOT PRO M1 and DEEBOT PRO K1VAC devices have a vulnerability in their WebSocket communication authentication mechanism, potentially allowing man-in-the-middle attacks. This vulnerability can be exploited by analyzing traffic data, potentially [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-66405 was published on 2026-08-10T09:17:22.637Z and has not been modified since then. The vulnerability affects DEEBOT PRO M1 and DEEBOT PRO K1VAC, which leave telnet servers enabled. This may be leveraged to log in to the affected products. Organizations using these products should verify and address the telne [truncated]