|
[Japanese]
|
JVNDB-2026-026400
|
Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
|
Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.- web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403
- Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404
- telnet server remains enabled (CWE-489) - CVE-2026-66405
- Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406
- A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.
- Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407
- A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.
- Weak password for root account (CWE-1391) - CVE-2026-66408
- Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409
- Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410
- Dependency on vulnerable third-party component (CWE-1395)
- Known vulnerability in Quectel EG25-G device (CVE-2021-31698)
- Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411
Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOTICS, and reported to JPCERT/CC to notify users of the solutions through JVN.
|
CVSS V3 Severity: Base Metrics 7.5 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2026-66403 |
CVSS v3 Severity Base Metrics:6.5 (Medium) [Other]- Access Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66404
|
CVSS v3 Severity Base Metrics:8.0 (High) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-66405
|
CVSS v3 Severity Base Metrics:4.8 (Medium) [Other]- Access Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): Low
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66406
|
CVSS v3 Severity Base Metrics:8.1 (High) [Other]- Access Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-66407
|
CVSS v3 Severity Base Metrics:4.6 (Medium) [Other]- Access Vector: Physical
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): None
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66408
|
CVSS v3 Severity Base Metrics:5.3 (Medium) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): Low
- Integrity Impact(I): None
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66409
|
CVSS v3 Severity Base Metrics:4.8 (Medium) [Other]- Access Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): Low
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66410
|
CVSS v3 Severity Base Metrics:5.3 (Medium) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): None
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-66411
|
|
ECOVACS
- ECOVACS PRO Android App prior to 1.3.82 (CVE-2026-66410)
- ECOVACS PRO iOS App prior to 1.3.82 (CVE-2026-66410)
Hellohas Robotics Inc.
- DEEBOT PRO M1 prior to M1-1.7.27 (CVE-2026-66403, CVE-2026-66404, CVE-2026-66405, CVE-2026-66406, CVE-2026-66407, CVE-2026-66408, CVE-2026-66409, CVE-2021-31698, CVE-2026-66411)
- DEEBOT PRO K1VAC prior to V1.7.821 (CVE-2026-66403, CVE-2026-66404, CVE-2026-66405, CVE-2026-66406, CVE-2026-66407, CVE-2026-66408, CVE-2026-66409, CVE-2021-31698, CVE-2026-66411)
|
|
- Floor map and log information stored on the product may be retrieved (CVE-2026-66403).
- Operation logs and activity logs stored on the product may be retrieved (CVE-2026-66404).
- telnet service may be leveraged to log in to the affected product (CVE-2026-66405).
- Arbitrary code may be executed with the administrative privilege (CVE-2026-66406).
- An attacker may obtain and/or alter communications of the product (CVE-2026-66407, CVE-2026-66410).
- The product's root password may be obtained by an attacker with physical access (CVE-2026-66408).
- An attacker may analyze and obtain the hotspot password and connect to the robot's access point (CVE-2026-66409).
- An arbitrary code may be executed on the product due to the known vulnerability in Quectel EG25-G devices (CVE-2021-31698) used in the product.
- An attacker may connect without authentication and operate the affected robot (CVE-2026-66411).
|
According to Hellohas Robotics Inc., all users are notified and all affected products are updated.
|
Hellohas Robotics Inc.
|
- Use of Weak Credentials(CWE-1391) [Other]
- Dependency on Vulnerable Third-Party Component(CWE-1395) [Other]
- Improper Certificate Validation(CWE-295) [Other]
- Incorrect Implementation of Authentication Algorithm(CWE-303) [Other]
- Use of a Broken or Risky Cryptographic Algorithm(CWE-327) [Other]
- Active Debug Code(CWE-489) [Other]
|
- CVE-2021-31698
- CVE-2026-66403
- CVE-2026-66404
- CVE-2026-66405
- CVE-2026-66406
- CVE-2026-66407
- CVE-2026-66408
- CVE-2026-66409
- CVE-2026-66410
- CVE-2026-66411
|
- JVN : JVNVU#92804348
|
- [2026/08/04]
Web page was published
|