CVE-2026-66408: Medium severity vulnerability
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Change the DEEBOT PRO M1 root account password from a weak password to a strong, strongly unpredictable password.
DEEBOT PRO M1 root account root password strength = strong/strongly unpredictable (replace weak password) - Configuration
Change the DEEBOT PRO K1V AC root account password from a weak password to a strong, strongly unpredictable password.
DEEBOT PRO K1V AC root account root password strength = strong/strongly unpredictable (replace weak password)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66408?
The severity of CVE-2026-66408 is medium, with a CVSS score of 4.6.
How do I fix CVE-2026-66408?
To mitigate CVE-2026-66408, reset the root account password to a strong and unique password.
Who is affected by CVE-2026-66408?
CVE-2026-66408 affects users of DEEBOT PRO M1 and DEEBOT PRO K1VAC devices.
What type of access is required to exploit CVE-2026-66408?
Exploiting CVE-2026-66408 requires physical access to the affected DEEBOT products.
What impact does CVE-2026-66408 have on confidentiality?
CVE-2026-66408 poses a significant risk to confidentiality as it allows unauthorized access to the root account.