JVNVU#92804348
Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Overview
Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.
Products Affected
CVE-2026-66403, CVE-2026-66404, CVE-2026-66405, CVE-2026-66406, CVE-2026-66407, CVE-2026-66408, CVE-2026-66409, CVE-2021-31698, CVE-2026-66411
- DEEBOT PRO M1 prior to M1-1.7.27
- DEEBOT PRO K1VAC prior to V1.7.821
- Android App "ECOVACS PRO" prior to 1.3.82
- iOS App "ECOVACS PRO" prior to 1.3.82
Description
Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.
- web server for debugging purposes remains enabled (CWE-489)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
- CVE-2026-66403
- Missing server certificate verification in MQTT communications (CWE-295)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.0
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N Base Score 6.5
- CVE-2026-66404
- telnet server remains enabled (CWE-489)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.6
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.0
- CVE-2026-66405
- Missing server certificate verification in wget command (CWE-295)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 2.3
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 4.8
- CVE-2026-66406
- A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.
- Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 7.7
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 8.1
- CVE-2026-66407
- A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.
- Weak password for root account (CWE-1391)
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 5.1
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 4.6
- CVE-2026-66408
- Weak password for Wi-Fi hotspot network (CWE-1391)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.9
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 5.3
- CVE-2026-66409
- Improper server certificate verification in the smartphone app (CWE-295)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 2.3
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 4.8
- CVE-2026-66410
- Dependency on vulnerable third-party component (CWE-1395)
- Known vulnerability in Quectel EG25-G device (CVE-2021-31698)
- Incorrect implementation of authentication algorithm in Websocket communications (CWE-303)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Base Score 5.3
- CVE-2026-66411
Impact
- Floor map and log information stored on the product may be retrieved (CVE-2026-66403).
- Operation logs and activity logs stored on the product may be retrieved (CVE-2026-66404).
- telnet service may be leveraged to log in to the affected product (CVE-2026-66405).
- Arbitrary code may be executed with the administrative privilege (CVE-2026-66406).
- An attacker may obtain and/or alter communications of the product (CVE-2026-66407, CVE-2026-66410).
- The product's root password may be obtained by an attacker with physical access (CVE-2026-66408).
- An attacker may analyze and obtain the hotspot password and connect to the robot's access point (CVE-2026-66409).
- An arbitrary code may be executed on the product due to the known vulnerability in Quectel EG25-G devices (CVE-2021-31698) used in the product.
- An attacker may connect without authentication and operate the affected robot (CVE-2026-66411).
Solution
According to Hellohas Robotics Inc., all users are notified and all affected products are updated.
Vendor Status
| Vendor | Link |
| Hellohas Robotics Inc. | DEEBOT PRO M1 / K1 VAC Firmware Update Notice (Updated: March 31, 2026) (Text in Japanese) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOTICS, and reported to JPCERT/CC to notify users of the solutions through JVN.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-66403 |
|
CVE-2026-66404 |
|
|
CVE-2026-66405 |
|
|
CVE-2026-66406 |
|
|
CVE-2026-66407 |
|
|
CVE-2026-66408 |
|
|
CVE-2026-66409 |
|
|
CVE-2026-66410 |
|
|
CVE-2026-66411 |
|
| JVN iPedia |
|