The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper WebSocket Authentication Enables Key Retrieval and Traffic Tampering on Deebot Pro M1 and K1VAC |
Mon, 10 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered. | |
| Weaknesses | CWE-327 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-08-10T08:00:43.341Z
Reserved: 2026-07-27T00:45:20.457Z
Link: CVE-2026-66407
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T10:00:04Z
-
CWE-327
Use of a Broken or Risky Cryptographic Algorithm