What is CVE-2026-66405?
CVE-2026-66405 reveals that DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums leave the Telnet server enabled. This vulnerability may allow an attacker to remotely log into the affected devices. Disabling the Telnet service is recommended until a fix is provided by the manufacturer.
Azərbaycanca: CVE-2026-66405, DEEBOT PRO M1 və DEEBOT PRO K1VAC robot tozsoranlarında Telnet serverinin aktiv qaldığını göstərir. Bu zəiflik təcavüzkara təsirə məruz qalan cihaza uzaqdan daxil olma imkanı yarada bilər. İstehsalçı tərəfindən düzəldici yeniləmə tətbiq olunana qədər Telnet xidmətinin söndürülməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
What devices are affected by CVE-2026-66405?
This vulnerability specifically affects DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums.
How can I mitigate this vulnerability until the manufacturer provides an update?
As a temporary workaround until the manufacturer applies a fix, it is recommended to disable the Telnet service on the devices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.