CyberRota Analysis
AI-GeneratedThe DEEBOT PRO M1 and DEEBOT PRO K1VAC are vulnerable due to improper authentication in their WebSocket communication, allowing attackers to retrieve the private key through man-in-the-middle attacks. This vulnerability enables unauthorized access and manipulation of communication data, posing a significant risk to user privacy and device integrity. Organizations using these models should prioritize patching this issue to safeguard against potential exploitation.
Original NVD Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.