Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
Published: 2026-08-10
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The affected ECOVACS DEEBOT Pro M1 and K1VAC models use the wget utility with server certificate validation explicitly disabled, allowing a man‑in‑the‑middle to view or modify traffic to the device servers. When an attacker successfully intercepts or alters this communication, the device may execute arbitrary code with administrative privileges, compromising the entire robot system.

Affected Systems

The products impacted are ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. No specific firmware or hardware version numbers are listed in the advisory; any devices that run the current production firmware are likely vulnerable.

Risk and Exploitability

The CVSS score of 2.3 indicates low overall severity, and the EPSS score is not reported. The vulnerability is not catalogued in CISA's KEV list. Attackers would need to position themselves on the network path between the robot and its update or control servers; the disabling of SSL validation makes MITM straightforward, potentially raising the risk to a moderate level for exposed devices, especially if no network segmentation is in place.

Generated by OpenCVE AI on August 10, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any firmware update or security patch released by ECOVACS that re‑enables server certificate validation.
  • If an update is not yet available, isolate the device from untrusted networks or implement network segmentation to block MITM traffic.
  • Enable or enforce TLS server certificate verification in the device configuration, if the firmware allows it.
  • Continuously monitor device logs for unexpected or unauthorized communication patterns indicative of a MITM interception.

Generated by OpenCVE AI on August 10, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1
Vendors & Products Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Disabled SSL Validation in DEEBOT Pro Enables MITM and Remote Code Execution

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ecovacs Robotics Deebot Pro K1vac Deebot Pro M1
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T17:54:34.815Z

Reserved: 2026-07-27T00:45:20.457Z

Link: CVE-2026-66406

cve-icon Vulnrichment

Updated: 2026-08-10T17:54:29.760Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T09:17:22.773

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-66406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:25:49Z

Weaknesses
  • CWE-295

    Improper Certificate Validation