AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66407

HIGH · CVSS 8.1 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The DEEBOT PRO M1 and DEEBOT PRO K1VAC are vulnerable due to improper authentication in their WebSocket communication, allowing attackers to retrieve the private key through man-in-the-middle attacks. This vulnerability enables unauthorized access and manipulation of communication data, posing a significant risk to user privacy and device integrity. Organizations using these models should prioritize patching this issue to safeguard against potential exploitation.

CVE
CVE-2026-66407
Severity
HIGH
CVSS
8.1
EPSS
0.33%

Original NVD Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.