CVE-2026-66406
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-295
Validación incorrecta de certificados
Fecha de publicación:
10/08/2026
Última modificación:
10/08/2026
Descripción
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.<br />
A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
Impacto
Puntuación base 4.0
2.30
Gravedad 4.0
BAJA
Puntuación base 3.x
4.80
Gravedad 3.x
MEDIA


