CVE-2026-66409: Medium severity vulnerability
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Change the Wi‑Fi hotspot password on the DEEBOT PRO M1 from weak/default credentials to a strong, unique password to prevent attackers from analyzing and obtaining it.
DEEBOT PRO M1 Wi‑Fi hotspot Wi‑Fi hotspot password = Set a strong, non-default password - Configuration
Change the Wi‑Fi hotspot password on the DEEBOT PRO K1VAC from weak/default credentials to a strong, unique password to prevent attackers from analyzing and obtaining it.
DEEBOT PRO K1VAC Wi‑Fi hotspot Wi‑Fi hotspot password = Set a strong, non-default password
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66409?
The severity of CVE-2026-66409 is assessed as medium with a score of 5.3.
How do I fix CVE-2026-66409?
To fix CVE-2026-66409, ensure that the Wi-Fi hotspot networks of DEEBOT PRO M1 and DEEBOT PRO K1VAC use strong passwords.
What devices are affected by CVE-2026-66409?
CVE-2026-66409 affects the DEEBOT PRO M1 and DEEBOT PRO K1VAC robotic vacuum cleaners.
What type of attack does CVE-2026-66409 enable?
CVE-2026-66409 enables unauthorized access to the Wi-Fi hotspot network of the affected robots due to the use of weak passwords.
Is there any impact on data confidentiality due to CVE-2026-66409?
Yes, CVE-2026-66409 has a low impact on confidentiality as it allows potential attackers to connect to the robot's access point.