What is CVE-2026-66404?
CVE-2026-66404 is a vulnerability in DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums where server certificates in MQTT communications are not validated. This may allow an attacker to potentially retrieve sensitive operation and activity logs over the network. Users of affected products should apply security patches from the vendor when available.
Azərbaycanca: CVE-2026-66404 zəifliyi DEEBOT PRO M1 və DEEBOT PRO K1VAC robot tozsoranlarında MQTT rabitəsində server sertifikatlarının yoxlanılmaması ilə bağlıdır. Bu, şəbəkə üzərindən məxfi əməliyyat və fəaliyyət jurnallarının ələ keçirilməsinə səbəb ola bilər. Təsirə məruz qalan cihazların istifadəçiləri istehsalçı tərəfindən buraxılacaq təhlükəsizlik yeniləmələrini tətbiq etməlidirlər.
FAQ2
How can CVE-2026-66404 affect my DEEBOT PRO M1 device?
Due to this vulnerability, server certificates are not validated during MQTT communications, which could allow an attacker on the network to potentially retrieve sensitive information such as your operation and activity logs.
What should I do for the CVE-2026-66404 vulnerability on my DEEBOT PRO K1VAC?
You should apply the security patches released by the vendor to your device as soon as they become available.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.