[Japanese]

JVNDB-2026-026400

Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App

Overview

Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.
  • web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403
  • Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404
  • telnet server remains enabled (CWE-489) - CVE-2026-66405
  • Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406
    • A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.
  • Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407
    • A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.
  • Weak password for root account (CWE-1391) - CVE-2026-66408
  • Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409
  • Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410
  • Dependency on vulnerable third-party component (CWE-1395)
    • Known vulnerability in Quectel EG25-G device (CVE-2021-31698)
  • Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411
Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOTICS, and reported to JPCERT/CC to notify users of the solutions through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 7.5 (High) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2026-66403


CVSS v3 Severity
Base Metrics:6.5 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66404


CVSS v3 Severity
Base Metrics:8.0 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-66405


CVSS v3 Severity
Base Metrics:4.8 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66406


CVSS v3 Severity
Base Metrics:8.1 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-66407


CVSS v3 Severity
Base Metrics:4.6 (Medium) [Other]
  • Access Vector: Physical
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): None
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66408


CVSS v3 Severity
Base Metrics:5.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): None
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66409


CVSS v3 Severity
Base Metrics:4.8 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66410


CVSS v3 Severity
Base Metrics:5.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): None
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66411
Affected Products


ECOVACS
  • ECOVACS PRO Android App prior to 1.3.82 (CVE-2026-66410)
  • ECOVACS PRO iOS App prior to 1.3.82 (CVE-2026-66410)
Hellohas Robotics Inc.
  • DEEBOT PRO M1 prior to M1-1.7.27 (CVE-2026-66403, CVE-2026-66404, CVE-2026-66405, CVE-2026-66406, CVE-2026-66407, CVE-2026-66408, CVE-2026-66409, CVE-2021-31698, CVE-2026-66411)
  • DEEBOT PRO K1VAC prior to V1.7.821 (CVE-2026-66403, CVE-2026-66404, CVE-2026-66405, CVE-2026-66406, CVE-2026-66407, CVE-2026-66408, CVE-2026-66409, CVE-2021-31698, CVE-2026-66411)

Impact

  • Floor map and log information stored on the product may be retrieved (CVE-2026-66403).
  • Operation logs and activity logs stored on the product may be retrieved (CVE-2026-66404).
  • telnet service may be leveraged to log in to the affected product (CVE-2026-66405).
  • Arbitrary code may be executed with the administrative privilege (CVE-2026-66406).
  • An attacker may obtain and/or alter communications of the product (CVE-2026-66407, CVE-2026-66410).
  • The product's root password may be obtained by an attacker with physical access (CVE-2026-66408).
  • An attacker may analyze and obtain the hotspot password and connect to the robot's access point (CVE-2026-66409).
  • An arbitrary code may be executed on the product due to the known vulnerability in Quectel EG25-G devices (CVE-2021-31698) used in the product.
  • An attacker may connect without authentication and operate the affected robot (CVE-2026-66411).
Solution

According to Hellohas Robotics Inc., all users are notified and all affected products are updated.
Vendor Information

Hellohas Robotics Inc.
CWE (What is CWE?)

  1. Use of Weak Credentials(CWE-1391) [Other]
  2. Dependency on Vulnerable Third-Party Component(CWE-1395) [Other]
  3. Improper Certificate Validation(CWE-295) [Other]
  4. Incorrect Implementation of Authentication Algorithm(CWE-303) [Other]
  5. Use of a Broken or Risky Cryptographic Algorithm(CWE-327) [Other]
  6. Active Debug Code(CWE-489) [Other]
CVE (What is CVE?)

  1. CVE-2021-31698
  2. CVE-2026-66403
  3. CVE-2026-66404
  4. CVE-2026-66405
  5. CVE-2026-66406
  6. CVE-2026-66407
  7. CVE-2026-66408
  8. CVE-2026-66409
  9. CVE-2026-66410
  10. CVE-2026-66411
References

  1. JVN : JVNVU#92804348
Revision History

  • [2026/08/04]
      Web page was published