Impact
The firmware of Deebot Pro M1 and Deebot Pro K1VAC devices runs an unprotected telnet server that accepts authentication (CWE-489). Once an attacker can log in, they can execute arbitrary commands on the device, potentially altering configuration, exfiltrating data, or using the appliance as a foothold for further network attacks.
Affected Systems
The affected systems are ECOVACS Robotics Deebot Pro M1 and Deebot Pro K1VAC devices.
Risk and Exploitability
The CVSS score of 8.7 denotes high severity. EPSS data is not available and the vulnerability is not listed in CISA KEV, indicating that exploitation may not yet be widespread. Based on the description, it is inferred that the likely attack vector is a remote TCP connection to port 23, requiring valid or weak credentials to gain shell access.
OpenCVE Enrichment