VYPR

DEEBOT PRO M1

by Hello Has

CVEs (1)

  • CVE-2026-66407HigAug 10, 2026
    risk 0.53cvss 8.1epss

    DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.