CVE-2026-66408CWE-1391

CVE-2026-66408

Medium · published August 10, 2026

CVSS v3.1
4.6
EPSS
0%
Percentile
3.8
In the wild
Unconfirmed
What it is

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.

Physical access to an affected product may allow to obtain the password of the root account.

The record
Technical detail
CVSS v3.1
4.6 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00142 · 3.8th percentile
Weakness
CWE-1391 · Use of Weak Credentials
Published
2026-08-10T13:17Z
References (2)
EPSS history
Timeline
  • 10 AUG 08:01Z
    The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords
    cvelistv5