Junglewise Threat Intelligence

CVE-2026-66411: Ecovacs DEEBOT PRO authentication bypass in WebSocket

CVE-2026-66411 · Severity: medium · CVSS 5.3 · Published 2026-08-10

Technologies: Ecovacs DEEBOT PRO M1, Ecovacs DEEBOT PRO K1VAC. Vendors: Ecovacs.

Executive brief

Ecovacs DEEBOT PRO robotic cleaners (M1 and K1VAC models) fail to properly authenticate users connecting via WebSocket communications, allowing unauthenticated attackers to remotely connect and operate the robots. An attacker can take full control of the device, access stored maps and operation logs, and execute arbitrary commands without any authentication credentials.

Technical details

The vulnerability stems from incorrect implementation of the WebSocket authentication algorithm (CWE-303) in the affected robotic cleaners. The authentication mechanism fails to properly validate client credentials, allowing an unauthenticated network attacker to establish a WebSocket connection and issue commands to the device. The attack requires only network reachability to the device; no credentials, user interaction, or physical access are needed. An attacker can enumerate and retrieve sensitive data (floor maps, operation logs), issue control commands to operate the robot, and potentially execute arbitrary code with device privileges. Patches are available: M1 firmware M1-1.7.27 and later, K1VAC firmware V1.7.821 and later.

Affected products

  • Ecovacs DEEBOT PRO M1 prior to M1-1.7.27
  • Ecovacs DEEBOT PRO K1VAC prior to V1.7.821

Timeline

  • 2026-07-31: disclosed
  • 2026-01-31: patched: Initial patches released (M1-1.7.27, K1VAC-1.7.82)
  • 2026-03-23: patched: Updated patches released (K1VAC V1.7.821 and M1 library update)

References

Related threats