Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
Published: 2026-08-10
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The firmware of Deebot Pro M1 and Deebot Pro K1VAC devices runs an unprotected telnet server that accepts authentication (CWE-489). Once an attacker can log in, they can execute arbitrary commands on the device, potentially altering configuration, exfiltrating data, or using the appliance as a foothold for further network attacks.

Affected Systems

The affected systems are ECOVACS Robotics Deebot Pro M1 and Deebot Pro K1VAC devices.

Risk and Exploitability

The CVSS score of 8.7 denotes high severity. EPSS data is not available and the vulnerability is not listed in CISA KEV, indicating that exploitation may not yet be widespread. Based on the description, it is inferred that the likely attack vector is a remote TCP connection to port 23, requiring valid or weak credentials to gain shell access.

Generated by OpenCVE AI on August 10, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or block the telnet service on the device via its configuration or firmware settings.
  • Configure network firewalls or device access control lists to block inbound and outbound traffic on TCP port 23 from untrusted networks.
  • Enforce strong, unique credentials on the device, and enable additional authentication mechanisms if supported.
  • Check the vendor’s website for firmware updates that disable the telnet service and apply them when released.

Generated by OpenCVE AI on August 10, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1
Vendors & Products Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Telnet Service Enabled on Deebot Pro M1 and K1VAC

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
Weaknesses CWE-489
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ecovacs Robotics Deebot Pro K1vac Deebot Pro M1
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T17:52:26.583Z

Reserved: 2026-07-27T00:45:20.456Z

Link: CVE-2026-66405

cve-icon Vulnrichment

Updated: 2026-08-10T17:52:22.952Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T09:17:22.637

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-66405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:25:51Z

Weaknesses