AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66406

MEDIUM · CVSS 4.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The DEEBOT PRO M1 and DEEBOT PRO K1VAC are vulnerable due to the use of the wget command with server certificate validation disabled, which exposes them to potential man-in-the-middle attacks. This vulnerability could allow an attacker to intercept and modify communications, potentially leading to the execution of arbitrary code with administrative privileges. Users of these devices, particularly those in environments where security is critical, should prioritize addressing this issue to mitigate risks.

CVE
CVE-2026-66406
Severity
MEDIUM
CVSS
4.8
EPSS
0.15%

Original NVD Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.