Sceawere

Vulnerability Detail

CVE-2026-66405UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Telnet Service Exposure

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
ECOVACS ROBOTICS
Product
DEEBOT PRO M1
Attack Type
Active debug code
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-10T09:17:22.637Z",
  "pubdate": "2026-08-10T09:17:22.637Z",
  "executiveSummary": "The DEEBOT PRO M1 and DEEBOT PRO K1VAC products suffer from an insecure service configuration vulnerability where the telnet servers are left enabled by default.\nThis vulnerability exposes administrative network services directly to the local or adjacent network environment without adequate access controls or documented hardening measures.\nThe primary impact of this flaw is unauthorized remote access to the underlying operating system of the affected products.\nAn attacker with network connectivity to the targeted devices can leverage the active telnet service to establish interactive terminal sessions.\nThe risk implications include complete system compromise, potential extraction of sensitive configuration data, and unauthorized manipulation of device functionality.\nExploitation requirements are minimal, primarily requiring network reachability to the exposed telnet daemon running on the robotic devices.",
  "technicalDetails": "The root cause of this vulnerability lies in the residual deployment configuration of the embedded firmware, which fails to disable or properly restrict debugging and remote management interfaces prior to production release.\nThe vulnerable component is the telnet server daemon operating within the network protocol stack of the affected products.\nThe affected products are explicitly identified as DEEBOT PRO M1 and DEEBOT PRO K1VAC.\nThe network exposure involves active listening ports associated with the telnet protocol, typically TCP port 23, accessible via the local network interface.\nExploitation occurs through standard network interaction where an unauthorized user initiates a TCP connection to the device's telnet service.\nThe attack flow proceeds as follows: First, the adversary scans the local network or targets a specific IP address assigned to the DEEBOT PRO M1 or DEEBOT PRO K1VAC to identify open listening ports. Upon discovering that the telnet service is active, the attacker establishes a socket connection to the service port. The daemon responds with a login prompt or direct shell access depending on the internal authentication configuration. Once connected, the attacker can execute system commands, inspect running processes, modify system files, or deploy persistent malware payloads depending on the privilege level granted by the active daemon session.\nThe post-exploitation impact includes full administrative control over the robotic hardware, potential pivot capabilities into other segments of the local network topology, and the ability to intercept internal data transmissions or sensor feeds managed by the operating system."
}
CVE-2026-66405: Unauthenticated Telnet Service Exposure (HIGH Severity, CVSS: 8.8) - Sceawere