CyberRota Analysis
AI-GeneratedThe DEEBOT PRO M1 and DEEBOT PRO K1VAC vacuum cleaners are vulnerable due to a lack of server certificate validation in their MQTT communications, potentially allowing unauthorized access to operation and activity logs. This could lead to the exposure of sensitive user data and compromise privacy. Users and organizations utilizing these devices should prioritize addressing this vulnerability to mitigate risks associated with data leakage.
CVE
CVE-2026-66404
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%
Original NVD Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.