Impact
The vulnerability originates from a debugging web server that remains enabled on Deebot Pro M1 and K1VAC models, as stated in the description. Attackers are able to connect to this server from the local network and retrieve the device’s stored floor mapping data and log information, which can expose the layout of the user’s environment and usage patterns. This disclosure can compromise user privacy and operational security. The shortfall is classified as CWE‑489, reflecting an insufficient control over the debug interface.
Affected Systems
Both ECOVACS Robotics Deebot Pro M1 and Deebot Pro K1VAC are affected. The issue is present on all units that retain the default debugging web server configuration; specific firmware version numbers are not disclosed, so any currently installed firmware that has not been updated to disable the server is at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker who can reach the device over its local network can directly read the data without authentication, making the vulnerability readily exploitable for any user with network connectivity to the unit.
OpenCVE Enrichment