What is CVE-2026-66409?
DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums have weak passwords configured for their Wi-Fi hotspot networks. This vulnerability allows an attacker to analyze and obtain the password to connect to the affected robot's access point. Device owners should immediately change default passwords and update device firmware.
Azərbaycanca: DEEBOT PRO M1 və DEEBOT PRO K1VAC robot tozsoranlarının Wi-Fi hotspot şəbəkələrində zəif şifrələr təyin edilib. Bu zəiflik təcavüzkara şifrəni analiz edərək ələ keçirməyə və təsirlənən robotun giriş nöqtəsinə qoşulmağa imkan verir. Cihaz sahibləri dərhal default şifrələri dəyişdirməli və cihaz proqram təminatını yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-1188
FAQ1
What does the CVE-2026-66409 vulnerability allow in DEEBOT PRO M1 and K1VAC robot vacuums?
This vulnerability allows an attacker to analyze and obtain the weak password of the device's Wi-Fi hotspot network and connect to the affected robot's access point.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.