Junglewise Threat Intelligence

CVE-2026-66409: ECOVACS DEEBOT PRO weak Wi-Fi hotspot password

CVE-2026-66409 · Severity: medium · CVSS 5.3 · Published 2026-08-10

Technologies: Ecovacs DEEBOT PRO M1, Ecovacs DEEBOT PRO K1VAC. Vendors: Ecovacs.

Executive brief

DEEBOT PRO robotic vacuum cleaners are configured with weak, predictable Wi-Fi hotspot passwords. An attacker can analyze and guess the password to connect directly to the robot's access point, bypassing network security controls and gaining unauthorized access to the device's local network interface and sensitive data stored on it.

Technical details

This vulnerability (CVE-2026-66409) is a weak password implementation (CWE-1391) in the Wi-Fi hotspot network feature of DEEBOT PRO robots. The vulnerability allows an attacker with network proximity to analyze and predict the Wi-Fi password, gaining connection to the robot's access point without authentication. No special tools or authentication are required beyond the ability to interact with the Wi-Fi hotspot; the password can be cracked through conventional analysis or dictionary attacks. Successful exploitation grants an attacker direct access to the robot's network interface, enabling potential information disclosure or further compromise of the device. Patches are available in DEEBOT PRO M1 firmware version M1-1.7.27 and later, and DEEBOT PRO K1VAC version V1.7.821 and later.

Affected products

  • ECOVACS DEEBOT PRO M1 prior to M1-1.7.27
  • ECOVACS DEEBOT PRO K1VAC prior to V1.7.821

Timeline

  • 2026-07-31: disclosed
  • 2026-01-31: patched: Initial patches released; K1VAC received additional update on 2026-03-23
  • 2026-08-10: advisory

References

Related threats