Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
Published: 2026-08-10
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The affected ECOVACS DEEBOT Pro M1 and K1VAC models use the wget utility with server certificate validation explicitly disabled, allowing a man‑in‑the‑middle to view or modify traffic to the device servers. When an attacker successfully intercepts or alters this communication, the device may execute arbitrary code with administrative privileges, compromising the entire robot system.

Affected Systems

The products impacted are ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. No specific firmware or hardware version numbers are listed in the advisory; any devices that run the current production firmware are likely vulnerable.

Risk and Exploitability

The CVSS score of 2.3 indicates low overall severity, and the EPSS score is not reported. The vulnerability is not catalogued in CISA's KEV list. Attackers would need to position themselves on the network path between the robot and its update or control servers; the disabling of SSL validation makes MITM straightforward, potentially raising the risk to a moderate level for exposed devices, especially if no network segmentation is in place.

Generated by OpenCVE AI on August 10, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any firmware update or security patch released by ECOVACS that re‑enables server certificate validation.
  • If an update is not yet available, isolate the device from untrusted networks or implement network segmentation to block MITM traffic.
  • Enable or enforce TLS server certificate verification in the device configuration, if the firmware allows it.
  • Continuously monitor device logs for unexpected or unauthorized communication patterns indicative of a MITM interception.

Generated by OpenCVE AI on August 10, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Disabled SSL Validation in DEEBOT Pro Enables MITM and Remote Code Execution

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T08:00:25.140Z

Reserved: 2026-07-27T00:45:20.457Z

Link: CVE-2026-66406

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T09:30:03Z

Weaknesses
  • CWE-295

    Improper Certificate Validation