Executive brief
ECOVACS DEEBOT robotic cleaners leave a telnet debugging service enabled by default, allowing any network attacker to remotely log in and take full control of the device. An attacker can issue arbitrary commands with administrative privileges, access stored location maps and activity logs, and redirect the robot's movements or disable cleaning functions, impacting operations and privacy.
Technical details
CVE-2026-66405 is a disabled-by-default debugging service vulnerability (CWE-489) affecting telnet on DEEBOT PRO M1 and K1VAC robotic cleaners. The telnet service is left enabled in the firmware, requiring no authentication to connect over the network (AV:N). Once authenticated via telnet (which is trivial when no password is enforced), an attacker gains administrative shell access and can execute arbitrary commands with full system privileges, including file access, service manipulation, and code execution. The vulnerability was disclosed on 2026-07-31 and patches were released in January 2026 (M1-1.7.27, K1VAC-1.7.821) with a subsequent K1VAC update on 2026-03-23 (V1.7.821).
Affected products
- ECOVACS DEEBOT PRO M1 prior to M1-1.7.27
- ECOVACS DEEBOT PRO K1VAC prior to V1.7.821
Timeline
- 2026-07-31: disclosed
- 2026-01-31: patched: DEEBOT PRO M1 version M1-1.7.27 and K1VAC version K1VAC-1.7.82 released
- 2026-03-23: patched: DEEBOT PRO K1VAC version V1.7.821 released with additional fixes
- 2026-08-04: advisory: JVNVU#92804348 advisory updated
- 2026-08-10: other: CVE-2026-66405 published on NVD