CVE-2026-66404

MEDIUM
6.5CVSS v3
CVSS v2
0.13% EPSS (exploit probability)
CWE-295CWE

Description

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.

CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references