What is CVE-2026-66407?
CVE-2026-66407 affects DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums, which improperly implement authentication in WebSocket communication. This vulnerability allows the WebSocket private key to be retrieved through traffic analysis via a man-in-the-middle attack, potentially altering communication contents. Users should avoid untrusted network environments until a security update is released by the manufacturer.
Azərbaycanca: CVE-2026-66407 DEEBOT PRO M1 və DEEBOT PRO K1VAC robot tozsoranlarında WebSocket rabitəsində autentifikasiyanın düzgün tətbiq edilməməsi ilə bağlıdır. Bu zəiflik man-in-the-middle hücumu vasitəsilə trafik analizi ilə WebSocket özəl açarının əldə edilməsinə və rabitə məzmununun dəyişdirilməsinə imkan yaradır. Cihazlardan istifadə edənlər istehsalçı tərəfindən təhlükəsizlik yeniləməsi təqdim olunana qədər şübhəli şəbəkə mühitlərindən qaçınmalıdır.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which devices are affected by CVE-2026-66407?
This vulnerability affects DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums.
What could be the consequence if CVE-2026-66407 is exploited?
Through a man-in-the-middle attack, traffic analysis could retrieve the WebSocket private key and potentially alter the communication contents.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.