CVE-2026-66407
HIGH
NVD
CVSS Score
8.1
Severity
HIGH
Published
Aug 10, 2026
Vendor
unknown
Description
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.