Description
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may allow to obtain the password of the root account.
Published: 2026-08-10
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the pre‑configured root accounts on the Deebot Pro M1 and K1VAC robots, which use weak passwords that can be discovered with physical access. Attackers who obtain these credentials can log in as root, giving them full control over the device’s firmware, network interfaces, and sensor data. This enables unauthorized operation of the robot, theft of data, and potential use as a foothold in a broader network, threatening confidentiality, integrity, and availability of the device.

Affected Systems

ECOVACS Robotics’ Deebot Pro M1 and Deebot Pro K1VAC models

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not yet included in CISA’s KEV catalog. The attack requires physical possession of the device, making remote compromise unlikely without a physical breach. However, once accessed, an attacker can leverage the weak credentials to gain root access, making the risk significant for environments where the robots are physically vulnerable.

Generated by OpenCVE AI on August 10, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Change the default root passwords to strong, unique passwords on each device.
  • Restrict or disable remote root access features such as SSH or network management interfaces if not needed.
  • Regularly apply any firmware updates released by ECOVACS that address authentication weaknesses.
  • Consider securing the physical environment to prevent unauthorized access to the robots.

Generated by OpenCVE AI on August 10, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Weak Root Passwords Enable Physical Access Compromise on DEEBOT Pro M1 and K1VAC

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.
Weaknesses CWE-1391
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T08:01:00.420Z

Reserved: 2026-07-27T00:45:20.457Z

Link: CVE-2026-66408

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T09:30:03Z

Weaknesses