What is CVE-2026-66408?
This vulnerability involves weak passwords configured for the root accounts of DEEBOT PRO M1 and K1VAC robot vacuums. Physical access to an affected product may allow an attacker to obtain the root password and gain full control over the device.
Azərbaycanca: Bu zəiflik DEEBOT PRO M1 və K1VAC robot tozsoranlarının root hesablarında zəif parolların istifadəsi ilə bağlıdır. Fiziki giriş əldə edən şəxs root parolunu ələ keçirərək cihazı tam nəzarətə götürə bilər.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Which device models are affected by CVE-2026-66408?
This vulnerability affects DEEBOT PRO M1 and K1VAC robot vacuums.
What is required for an attacker to exploit CVE-2026-66408?
An attacker must obtain physical access to the affected product.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.