CVE-2026-66409: Ecovacs Robotics Deebot Pro k1vac
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.
Affected products
- Ecovacs Robotics Deebot Pro k1vac: before V1.7.821 (fixed in V1.7.821)
- Ecovacs Robotics Deebot Pro m1: before M1-1.7.27 (fixed in M1-1.7.27)
Published 2026-08-10. Last modified 2026-08-28.