Sceawere

Vulnerability Detail

CVE-2026-66407UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DEEBOT PRO Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
4h ago
Vendor
ECOVACS ROBOTICS
Product
DEEBOT PRO M1
Attack Type
Use of a broken or risky cryptographic algorithm
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-10T09:17:22.917Z",
  "pubdate": "2026-08-10T09:17:22.917Z",
  "executiveSummary": "An improper authentication vulnerability exists in the WebSocket communication implementation of the DEEBOT PRO M1 and DEEBOT PRO K1VAC products. This security flaw allows unauthorized entities to compromise the confidentiality and integrity of the real-time data stream passing between the client and the affected devices. The primary risk implication is the potential for complete session compromise and unauthorized remote manipulation of device functions. By leveraging a man-in-the-middle attack vector, an external threat actor with network access to the communication path can passively capture traffic data and subsequently extract the sensitive WebSocket private key. Once the private key is acquired, the attacker possesses the capability to intercept, decrypt, and actively alter communication contents in transit. The exploitation of this vulnerability requires the attacker to be in a network position capable of intercepting traffic, such as a compromised local area network or a rogue access point, but requires no prior authentication to the device itself. Consequently, this exposes the affected systems to severe operational interference and unauthorized command injection.",
  "technicalDetails": "The vulnerability resides within the WebSocket communication subsystem of DEEBOT PRO M1 and DEEBOT PRO K1VAC. The root cause of the issue stems from an improper authentication design and weak cryptographic key handling during the establishment or maintenance of the WebSocket protocol connection. Specifically, the mechanism utilized to derive, negotiate, or transmit authentication credentials fails to adequately protect the WebSocket private key from unauthorized disclosure.\nExploitation of this vulnerability occurs via a man-in-the-middle attack methodology. The attack flow proceeds in several distinct steps. First, the attacker positions themselves on the network path between the targeted DEEBOT PRO device and the legitimate control application or server. As network traffic traverses this path, the attacker captures the raw WebSocket communication data. Through rigorous traffic analysis of the captured payloads, the attacker identifies and extracts the hardcoded, predictably derived, or unencrypted WebSocket private key.\nFollowing the successful retrieval of the private key, the attacker gains the requisite cryptographic material to bypass the intended authentication controls of the WebSocket channel. The attacker can then establish unauthorized authenticated sessions or spoof legitimate client connections. Because the protocol implementation lacks robust message integrity verification and mutual authentication tied securely to hardware trust anchors, the attacker's payload behavior includes the ability to inject malicious commands, modify legitimate control instructions in transit, and forge server or client responses.\nThe vulnerable component is the WebSocket communication handler responsible for session establishment and message authentication. Network exposure is present wherever the devices communicate over insecure or unsegmented local networks susceptible to interception. No prior privileges or authentication credentials are required by the attacker prior to executing the man-in-the-middle interception and key extraction phase. The resulting post-exploitation impact includes unauthorized remote control, state alteration, and arbitrary manipulation of device operations."
}
CVE-2026-66407: DEEBOT PRO Authentication Bypass Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere