CVE-2026-66403: High severity vulnerability
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the web server that has been left enabled for debugging purposes on DEEBOT PRO M1.
DEEBOT PRO M1 web server (debugging mode) = disabled - Configuration
Disable the web server that has been left enabled for debugging purposes on DEEBOT PRO K1VAC.
DEEBOT PRO K1VAC web server (debugging mode) = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66403?
CVE-2026-66403 has a severity rating of 7.5, indicating a high level of risk.
How do I fix CVE-2026-66403?
To mitigate CVE-2026-66403, disable the web server used for debugging purposes on the affected DEEBOT models.
What products are affected by CVE-2026-66403?
CVE-2026-66403 affects the DEEBOT PRO M1 and DEEBOT PRO K1VAC models.
What kind of information can be retrieved due to CVE-2026-66403?
Due to CVE-2026-66403, the floor map and log information stored on the affected devices may be accessible.
What is the impact of CVE-2026-66403?
CVE-2026-66403 could lead to unauthorized access to sensitive data stored in the affected DEEBOT devices.