The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac Ecovacs Robotics deebot Pro M1 |
|
| Vendors & Products |
Ecovacs Robotics
Ecovacs Robotics deebot Pro K1vac Ecovacs Robotics deebot Pro M1 |
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper WebSocket Authentication Enables Key Retrieval and Traffic Tampering on Deebot Pro M1 and K1VAC |
Mon, 10 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered. | |
| Weaknesses | CWE-327 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-08-10T17:55:21.647Z
Reserved: 2026-07-27T00:45:20.457Z
Link: CVE-2026-66407
Updated: 2026-08-10T17:55:17.971Z
Status : Received
Published: 2026-08-10T09:17:22.917
Modified: 2026-08-10T18:18:49.800
Link: CVE-2026-66407
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:25:47Z