Impact
The vulnerability resides in the pre‑configured root accounts on the Deebot Pro M1 and K1VAC robots, which use weak passwords that can be discovered with physical access. Attackers who obtain these credentials can log in as root, giving them full control over the device’s firmware, network interfaces, and sensor data. This enables unauthorized operation of the robot, theft of data, and potential use as a foothold in a broader network, threatening confidentiality, integrity, and availability of the device.
Affected Systems
ECOVACS Robotics’ Deebot Pro M1 and Deebot Pro K1VAC models
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not yet included in CISA’s KEV catalog. The attack requires physical possession of the device, making remote compromise unlikely without a physical breach. However, once accessed, an attacker can leverage the weak credentials to gain root access, making the risk significant for environments where the robots are physically vulnerable.
OpenCVE Enrichment