Impact
The vulnerability lies in the incorrect implementation of the authentication algorithm used in WebSocket communications of Ecovacs Deebot robots. Because the algorithm fails to enforce authentication, an unauthenticated attacker can establish a WebSocket connection and issue arbitrary control commands to the robot. This allows the attacker to manipulate the device’s behavior and potentially disrupt normal operations or compromise user privacy.
Affected Systems
Ecovacs Robotics devices affected are the Deebot Pro M1 and Deebot Pro K1VAC. No firmware version range is provided in the advisory; therefore, any device running the default or unpatched firmware is potentially vulnerable. This information is inferred from the lack of version details in the references and description.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by connecting to the robot’s WebSocket port if they have network access to the device. The absence of authentication enforcement lowers the barrier to exploitation, although network proximity is required. The risk is further amplified if the robot is exposed to the internet or poorly protected local networks.
OpenCVE Enrichment