Vulnerabilidades en ECOVACS ROBOTICS
9 resultadosAnálisis Vexday
A Ecovacs Robotics registra 9 vulnerabilidades na base, todas publicadas nos últimos 90 dias, indicando descoberta recente de problemas de segurança. Nenhuma dessas falhas está sob exploração ativa (KEV) ou classificada como crítica, reduzindo o risco imediato. A fraqueza dominante é CWE-295 (validação inadequada de certificados SSL/TLS), padrão em dispositivos IoT com implementação débil de comunicação segura.
CVE-2026-66408MEDIUMThe root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may alloEPSS —CVE-2026-66411MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.
An unauthenticated attacker EPSS —CVE-2026-66403HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affeEPSS —CVE-2026-66405HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.EPSS —CVE-2026-66406LOWDEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obEPSS —CVE-2026-66407HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.
The WebSocket private key may be retrievEPSS —CVE-2026-66410LOWAndroid and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.EPSS —CVE-2026-66404MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on thEPSS —CVE-2026-66409MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obEPSS —