CVE-2026-66404: Medium severity DEEBOT PRO M1 vulnerability
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66404?
The severity of CVE-2026-66404 is categorized as medium with a score of 6.5.
What vulnerabilities exist in CVE-2026-66404?
CVE-2026-66404 involves the DEEBOT PRO M1 and DEEBOT PRO K1VAC not validating server certificates in MQTT communications.
How does CVE-2026-66404 affect user privacy?
CVE-2026-66404 can lead to unauthorized retrieval of operation logs and activity logs stored on the affected products, potentially compromising user privacy.
How do I mitigate the risks associated with CVE-2026-66404?
To mitigate CVE-2026-66404, ensure that your DEEBOT PRO M1 and DEEBOT PRO K1VAC devices are updated with any available security patches released by the manufacturer.
What types of devices are impacted by CVE-2026-66404?
CVE-2026-66404 specifically impacts the DEEBOT PRO M1 and DEEBOT PRO K1VAC devices.