CVE-2026-66411: Medium severity vulnerability
Published Aug 10, 2026
·Updated
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot.
Event History
Aug 10, 2026
CVE Published
via MITRE·08:13 AM
Data Sourced
via MITRE·08:13 AM
DescriptionSeverity
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66411?
CVE-2026-66411 has a medium severity rating of 5.3.
2
What are the potential impacts of CVE-2026-66411?
CVE-2026-66411 allows an unauthenticated attacker to connect and operate the affected DEEBOT robots.
3
How do I fix CVE-2026-66411?
To mitigate CVE-2026-66411, it's advised to apply any provided firmware updates from the manufacturer that address the authentication algorithm.
4
Which devices are affected by CVE-2026-66411?
CVE-2026-66411 affects the DEEBOT PRO M1 and DEEBOT PRO K1VAC models.
5
What type of attack is associated with CVE-2026-66411?
CVE-2026-66411 is associated with unauthorized access due to improper authentication in Websocket communications.