Vulnerabilidades em ECOVACS ROBOTICS
9 resultadosAnálise Vexday
A Ecovacs Robotics registra 9 vulnerabilidades na base, todas publicadas nos últimos 90 dias, indicando descoberta recente de problemas de segurança. Nenhuma dessas falhas está sob exploração ativa (KEV) ou classificada como crítica, reduzindo o risco imediato. A fraqueza dominante é CWE-295 (validação inadequada de certificados SSL/TLS), padrão em dispositivos IoT com implementação débil de comunicação segura.
CVE-2026-66405HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.EPSS 0.5%CVE-2026-66403HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affeEPSS 0.4%CVE-2026-66411MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.
An unauthenticated attacker EPSS 0.4%CVE-2026-66407HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.
The WebSocket private key may be retrievEPSS 0.3%CVE-2026-66409MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obEPSS 0.3%CVE-2026-66408MEDIUMThe root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may alloEPSS 0.2%CVE-2026-66404MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on thEPSS 0.2%CVE-2026-66410LOWAndroid and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.EPSS 0.2%CVE-2026-66406LOWDEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obEPSS 0.2%