DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1
Vendors & Products Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac
Ecovacs Robotics deebot Pro M1

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Telnet Service Enabled on Deebot Pro M1 and K1VAC

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
Weaknesses CWE-489
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2026-08-10T07:59:40.861Z

Updated: 2026-08-10T17:52:26.583Z

Reserved: 2026-07-27T00:45:20.456Z

Link: CVE-2026-66405

cve-icon Vulnrichment

Updated: 2026-08-10T17:52:22.952Z

cve-icon NVD

Status : Received

Published: 2026-08-10T09:17:22.637

Modified: 2026-08-10T18:18:49.550

Link: CVE-2026-66405

cve-icon Redhat

No data.