What is CVE-2026-66411?
CVE-2026-66411 is an improper implementation of the authentication algorithm in WebSocket communications affecting DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums. This allows an unauthenticated attacker to connect and operate the affected device. Network access to these devices should be restricted until a patch is applied.
Azərbaycanca: CVE-2026-66411, DEEBOT PRO M1 və DEEBOT PRO K1VAC robot tozsoranlarında WebSocket rabitəsi zamanı autentifikasiya alqoritminin səhv tətbiq edilməsidir. Bu zəiflik autentifikasiya olunmamış hücumçuya cihaza qoşulub onu idarə etməyə imkan verir. İstehsalçı tərəfindən yamaq təqdim olunana qədər cihazların şəbəkə əlçatanlığı məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which DEEBOT models are affected by CVE-2026-66411?
This vulnerability affects DEEBOT PRO M1 and DEEBOT PRO K1VAC robot vacuums.
How can the device be protected until a patch is applied?
Network access to these devices should be restricted until a patch is provided by the manufacturer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.