---
cve: "CVE-2026-66408"
severity: "MEDIUM"
cvss: 5.1
epss: "20%"
vendor: "ECOVACS ROBOTICS"
kev: false
exploited: false
published: "2026-08-10 09:17:23"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-02T09:54:52+02:00"
---

# CVE-2026-66408

> 5.1 MEDIUM

## Beschreibung

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may allow to obtain the password of the root account.

## CVSS-Vektor

```
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Physisch | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://robot.hellohas.co.jp/news/update_20260331/>
- <https://jvn.jp/en/vu/JVNVU92804348/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-66408) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
