Executive brief
ECOVACS DEEBOT PRO robotic vacuum cleaners (M1 and K1VAC models) are configured with weak passwords for the root administrator account. An attacker with physical access to the device can obtain the root password through reverse engineering or analysis, leading to complete system compromise and unauthorized control of the robot, access to stored maps and logs, and potential network access if the device is connected to the home network.
Technical details
The vulnerability is a weak password configuration (CWE-1391) affecting the root account on DEEBOT PRO M1 (prior to M1-1.7.27) and DEEBOT PRO K1VAC (prior to V1.7.821). The attack requires physical access to the device to extract or analyze the password, allowing an attacker to gain administrative privileges. Once root access is obtained, an attacker can execute arbitrary commands, modify device configuration, access stored floor maps and activity logs, and potentially use the device as a pivot point into the home network. Patches are available; Hellohas Robotics released firmware updates in January 2026 (M1-1.7.27, K1VAC-1.7.82) with a follow-up library update for M1 in March 2026.
Affected products
- ECOVACS DEEBOT PRO M1 prior to M1-1.7.27
- ECOVACS DEEBOT PRO K1VAC prior to V1.7.821
Timeline
- 2026-07-31: disclosed
- 2026-01-31: patched: Firmware versions M1-1.7.27 and K1VAC-1.7.82 released; K1VAC further updated March 23, 2026 to V1.7.821