CVE-2026-66407: High severity vulnerability
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66407?
CVE-2026-66407 has a severity rating of 8.1 on the CVSS scale.
How do I fix CVE-2026-66407?
To mitigate CVE-2026-66407, update the DEEBOT PRO M1 and DEEBOT PRO K1VAC firmware to the latest version provided by the manufacturer.
What are the risks associated with CVE-2026-66407?
CVE-2026-66407 allows attackers to perform man-in-the-middle attacks, potentially compromising authentication and altering communication.
Can CVE-2026-66407 be exploited remotely?
Yes, CVE-2026-66407 is vulnerable to remote exploitation due to its improper implementation of authentication in WebSocket communication.
What devices are affected by CVE-2026-66407?
CVE-2026-66407 affects the DEEBOT PRO M1 and DEEBOT PRO K1VAC robotic vacuum cleaners.