Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obtained to connect to the access point of an affected robot.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

DEEBOT PRO M1 and DEEBOT PRO K1VAC robots are configured with weak passwords for their Wi‑Fi hotspot networks. Because a weak password can be analyzed and discovered, an attacker can connect to the robot’s access point and gain network access to the device. This is an intentional flaw in authentication, identified as CWE‑1391. The impact is the ability to connect to the hotspot and potentially issue commands or read information from the robot’s local network, compromising confidentiality and integrity of device operation. The weakness does not directly lead to remote code execution but enables unauthorized network access and control of the affected robots.

Affected Systems

Ecovacs Robotics Deebot Pro M1 and Deebot Pro K1VAC are affected. No specific product versions are listed in the advisory, so the vulnerability may exist in all current builds that use the default hotspot password. If you operate these devices, check the firmware version and apply any vendor updates that address hotspot password configuration.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate risk. EPSS information is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is local network proximity to the robot’s Wi‑Fi hotspot; an attacker within range can analyze the weak password and join the network. The simplicity of the weakness makes it relatively easy to exploit, but it requires physical or local network access, which may limit the breadth of exposure. Mitigation through updated firmware or stronger passwords will reduce the risk considerably.

Generated by OpenCVE AI on August 10, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the robot’s firmware to the latest version that removes the weak hotspot password or implements proper password policies as announced by Ecovacs
  • Configure a strong, unique password for the Deebot’s Wi‑Fi hotspot; avoid defaults and enforce a minimum length and character variety
  • Disable the Wi‑Fi hotspot feature if not required for operation to reduce exposure

Generated by OpenCVE AI on August 10, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1
Vendors & Products Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Weak Wi‑Fi Hotspot Passwords Enable Unauthenticated Access on Deebot Robots

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.
Weaknesses CWE-1391
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ecovacs Robotics Deebot Pro K1vac Deebot Pro M1
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T18:05:13.772Z

Reserved: 2026-07-27T00:45:20.457Z

Link: CVE-2026-66409

cve-icon Vulnrichment

Updated: 2026-08-10T18:04:59.827Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T09:17:23.210

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-66409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:25:43Z

Weaknesses