Impact
The affected ECOVACS DEEBOT Pro M1 and K1VAC models use the wget utility with server certificate validation explicitly disabled, allowing a man‑in‑the‑middle to view or modify traffic to the device servers. When an attacker successfully intercepts or alters this communication, the device may execute arbitrary code with administrative privileges, compromising the entire robot system.
Affected Systems
The products impacted are ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. No specific firmware or hardware version numbers are listed in the advisory; any devices that run the current production firmware are likely vulnerable.
Risk and Exploitability
The CVSS score of 2.3 indicates low overall severity, and the EPSS score is not reported. The vulnerability is not catalogued in CISA's KEV list. Attackers would need to position themselves on the network path between the robot and its update or control servers; the disabling of SSL validation makes MITM straightforward, potentially raising the risk to a moderate level for exposed devices, especially if no network segmentation is in place.
OpenCVE Enrichment