Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.
The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
Published: 2026-08-10
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in an improper implementation of authentication for WebSocket communication on certain robotic vacuum devices. An attacker can perform a man‑in‑the‑middle interception to obtain the WebSocket private key used by the device. With that key they can decrypt and alter the contents of the WebSocket traffic, allowing manipulation of commands or data exchanged between the device and its controlling application. This flaw is categorized as CWE‑327, indicating the use of insecure cryptographic practices.

Affected Systems

The affected products are ECOVACS Robotics’ Deebot Pro M1 and Deebot Pro K1VAC models. No specific firmware or version numbers are disclosed here, so all currently deployed devices running these models are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.7 reflects a high severity with potential for significant impact on integrity and confidentiality. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation reports at this time. The likely attack path involves a network‑level man‑in‑the‑middle that can observe and alter traffic to the device. Because the attacker requires proximity or control over the network segment the device uses, the risk is elevated for systems with open or poorly segmented networks but may be lower in highly isolated or protected environments.

Generated by OpenCVE AI on August 10, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied firmware patch or update for the affected Deebot Pro models immediately.
  • Limit the device’s exposure by placing it in a dedicated VLAN or applying firewall rules that restrict inbound WebSocket traffic to known, trusted endpoints.
  • Implement network monitoring and IDS/IPS rules to detect abnormal WebSocket activity or credential interception attempts.

Generated by OpenCVE AI on August 10, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1
Vendors & Products Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper WebSocket Authentication Enables Key Retrieval and Traffic Tampering on Deebot Pro M1 and K1VAC

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ecovacs Robotics Deebot Pro K1vac Deebot Pro M1
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T17:55:21.647Z

Reserved: 2026-07-27T00:45:20.457Z

Link: CVE-2026-66407

cve-icon Vulnrichment

Updated: 2026-08-10T17:55:17.971Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T09:17:22.917

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-66407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:25:47Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm