CVE-2026-66404
MEDIUM6.5CVSS v3
—CVSS v2
0.13%
EPSS (exploit probability)
CWE-295CWE
Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.