Impact
DEEBOT PRO M1 and DEEBOT PRO K1VAC robots are configured with weak passwords for their Wi‑Fi hotspot networks. Because a weak password can be analyzed and discovered, an attacker can connect to the robot’s access point and gain network access to the device. This is an intentional flaw in authentication, identified as CWE‑1391. The impact is the ability to connect to the hotspot and potentially issue commands or read information from the robot’s local network, compromising confidentiality and integrity of device operation. The weakness does not directly lead to remote code execution but enables unauthorized network access and control of the affected robots.
Affected Systems
Ecovacs Robotics Deebot Pro M1 and Deebot Pro K1VAC are affected. No specific product versions are listed in the advisory, so the vulnerability may exist in all current builds that use the default hotspot password. If you operate these devices, check the firmware version and apply any vendor updates that address hotspot password configuration.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate risk. EPSS information is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is local network proximity to the robot’s Wi‑Fi hotspot; an attacker within range can analyze the weak password and join the network. The simplicity of the weakness makes it relatively easy to exploit, but it requires physical or local network access, which may limit the breadth of exposure. Mitigation through updated firmware or stronger passwords will reduce the risk considerably.
OpenCVE Enrichment