Executive brief
DEEBOT PRO robotic vacuum cleaners are configured with weak, predictable Wi-Fi hotspot passwords. An attacker can analyze and guess the password to connect directly to the robot's access point, bypassing network security controls and gaining unauthorized access to the device's local network interface and sensitive data stored on it.
Technical details
This vulnerability (CVE-2026-66409) is a weak password implementation (CWE-1391) in the Wi-Fi hotspot network feature of DEEBOT PRO robots. The vulnerability allows an attacker with network proximity to analyze and predict the Wi-Fi password, gaining connection to the robot's access point without authentication. No special tools or authentication are required beyond the ability to interact with the Wi-Fi hotspot; the password can be cracked through conventional analysis or dictionary attacks. Successful exploitation grants an attacker direct access to the robot's network interface, enabling potential information disclosure or further compromise of the device. Patches are available in DEEBOT PRO M1 firmware version M1-1.7.27 and later, and DEEBOT PRO K1VAC version V1.7.821 and later.
Affected products
- ECOVACS DEEBOT PRO M1 prior to M1-1.7.27
- ECOVACS DEEBOT PRO K1VAC prior to V1.7.821
Timeline
- 2026-07-31: disclosed
- 2026-01-31: patched: Initial patches released; K1VAC received additional update on 2026-03-23
- 2026-08-10: advisory