Impact
The vulnerability lies in an improper implementation of authentication for WebSocket communication on certain robotic vacuum devices. An attacker can perform a man‑in‑the‑middle interception to obtain the WebSocket private key used by the device. With that key they can decrypt and alter the contents of the WebSocket traffic, allowing manipulation of commands or data exchanged between the device and its controlling application. This flaw is categorized as CWE‑327, indicating the use of insecure cryptographic practices.
Affected Systems
The affected products are ECOVACS Robotics’ Deebot Pro M1 and Deebot Pro K1VAC models. No specific firmware or version numbers are disclosed here, so all currently deployed devices running these models are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.7 reflects a high severity with potential for significant impact on integrity and confidentiality. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation reports at this time. The likely attack path involves a network‑level man‑in‑the‑middle that can observe and alter traffic to the device. Because the attacker requires proximity or control over the network segment the device uses, the risk is elevated for systems with open or poorly segmented networks but may be lower in highly isolated or protected environments.
OpenCVE Enrichment