CVE-2026-66405: High severity vulnerability
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the Telnet server on DEEBOT PRO M1 to prevent telnet-based login to the affected product.
DEEBOT Pro M1 Telnet server = disabled - Configuration
Disable the Telnet server on DEEBOT PRO K1VAC to prevent telnet-based login to the affected product.
DEEBOT Pro K1VAC Telnet server = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66405?
CVE-2026-66405 has a high severity rating of 8.8.
How can I fix CVE-2026-66405?
To fix CVE-2026-66405, disable the telnet service on the DEEBOT PRO M1 and DEEBOT PRO K1VAC devices.
What devices are affected by CVE-2026-66405?
The affected devices for CVE-2026-66405 are the DEEBOT PRO M1 and DEEBOT PRO K1VAC.
What risks are associated with CVE-2026-66405?
CVE-2026-66405 poses risks such as unauthorized access through the enabled telnet service.
Is remote access a factor in CVE-2026-66405?
Yes, CVE-2026-66405 allows for remote access due to the enabled telnet servers.