VYPR
Vendor

Hellohas

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2026-66405HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

  • CVE-2026-66407HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.

  • CVE-2026-66409MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.

  • CVE-2026-66406MedAug 10, 2026
    risk 0.31cvss 4.8epss 0.00

    DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.