Sceawere
Vulnerability Detail
CVE-2026-66408UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Weak Root Password Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.6
- Creation Date
- 4h ago
- Vendor
- ECOVACS ROBOTICS
- Product
- DEEBOT PRO M1
- Attack Type
- Use of weak credentials
- Vector String
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.6",
"pubDate": "2026-08-10T09:17:23.060Z",
"pubdate": "2026-08-10T09:17:23.060Z",
"executiveSummary": "An insecure configuration vulnerability exists affecting the root accounts of the DEEBOT PRO M1 and DEEBOT PRO K1VAC products. The root account utilizes a weak password, creating a significant security risk for deployed environments. The primary impact of this vulnerability is the potential compromise of administrative confidentiality and integrity on the underlying operating system. The risk implication is severe, as obtaining root-level access typically grants an attacker full control over the affected device, potentially leading to unauthorized surveillance, manipulation of device functions, or further pivoting within the local network. The capability required to exploit this issue involves physical access to the affected product. Exploitation requirements mandate that the threat actor is physically present with the device to interact with local interfaces or storage mediums to extract or brute-force the credential. No remote network exploitation vector is described in conjunction with this specific physical constraint, but the resulting compromise yields the highest level of privilege on the targeted embedded systems.",
"technicalDetails": "The root cause of the vulnerability stems from the implementation of insufficiently complex or default credentials for the superuser (root) account within the firmware configuration of the DEEBOT PRO M1 and DEEBOT PRO K1VAC systems. In embedded Linux and real-time operating systems common to robotics and smart appliances, the root account governs all system-level operations, daemons, hardware abstraction layers, and inter-process communications. The vulnerable component is the operating system authentication mechanism and credential storage configuration for the administrative root entity.\nAuthentication requirements for the vulnerable interface are bypassed or rendered ineffective due to the low entropy of the configured password, which makes it susceptible to standard credential recovery or authentication attacks. Privilege requirements are elevated post-exploitation, as successfully authenticating or deriving the root password grants immediate, unrestricted superuser privileges over the entire system. Network exposure is localized rather than remote, given that the threat model explicitly requires physical interaction with the hardware.\nThe attack flow proceeds in a sequential manner. First, the threat actor establishes physical access to an affected DEEBOT PRO M1 or DEEBOT PRO K1VAC product. Second, the attacker interacts with local hardware interfaces—such as exposed serial debugging headers (UART), JTAG interfaces, removable storage media, or accessible internal flash components—depending on the physical architecture of the device. Third, utilizing the physical access vector, the attacker extracts password hashes, configuration files containing plaintext or weakly hashed credentials, or directly interfaces with a terminal prompt where the weak root password can be supplied or bypassed. Finally, upon successful authentication or credential retrieval, the attacker attains root-level execution privileges, enabling complete post-exploitation control over the embedded Linux environment, including persistent access, firmware modification, interception of sensor telemetry, and control of actuation mechanisms."
}