Junglewise Threat Intelligence

CVE-2026-66404: Ecovacs DEEBOT PRO M1 and K1VAC missing MQTT server certificate verification

CVE-2026-66404 · Severity: medium · CVSS 6.5 · Published 2026-08-10

Technologies: Ecovacs DEEBOT PRO M1, Ecovacs DEEBOT PRO K1VAC. Vendors: Ecovacs.

Executive brief

Robotic vacuum cleaners DEEBOT PRO M1 and K1VAC fail to validate server certificates in MQTT communications, allowing attackers to intercept and retrieve stored operation logs and activity logs without authentication. An attacker positioned on the same network or performing a man-in-the-middle attack can capture sensitive activity data and robot movement history, compromising user privacy and potentially revealing patterns of home occupancy.

Technical details

The vulnerability is a missing server certificate verification issue (CWE-295) in MQTT communications used by the affected robotic vacuums. The devices do not properly validate TLS certificates when connecting to MQTT brokers, enabling man-in-the-middle (MITM) attacks. An attacker with network access or capable of intercepting traffic can impersonate the legitimate MQTT server and trick the device into sending operation logs and activity logs without authentication. The attack requires network-adjacent position or the ability to intercept/redirect traffic, but no prior authentication or special privileges. Patches addressing this vulnerability were released in January 2026 (firmware versions M1-1.7.27 and K1VAC-1.7.821), with an additional library update for M1 in March 2026.

Affected products

  • Ecovacs DEEBOT PRO M1 prior to M1-1.7.27
  • Ecovacs DEEBOT PRO K1VAC prior to V1.7.821

Timeline

  • 2026-07-31: disclosed: Vulnerability disclosed via JVNVU#92804348
  • 2026-01-31: patched: Initial patches released: M1-1.7.27 and K1VAC-1.7.821
  • 2026-03-23: patched: Additional library update for M1; V1.7.821 update for K1VAC
  • 2026-08-10: advisory: CVE-2026-66404 published on NVD

References

Related threats