<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 13:06:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-350652</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-350652</link>
      <description>EUVD-2026-350652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-350652</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66403</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66403</link>
      <description>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66403</guid>
    </item>
    <item>
      <title>GHSA-w22m-rfhf-hgj7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w22m-rfhf-hgj7</link>
      <description>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w22m-rfhf-hgj7</guid>
    </item>
    <item>
      <title>jvndb-2026-026400</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-026400</link>
      <description>&lt;p&gt;Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;telnet server remains enabled (CWE-489) - CVE-2026-66405&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Weak password for root account (CWE-1391) - CVE-2026-66408&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Dependency on vulnerable third-party component (CWE-1395)&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Known vulnerability in Quectel EG25-G device (CVE-2021-31698)&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;telnet server remains enabled (CWE-489) - CVE-2026-66405&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Weak password for root account (CWE-1391) - CVE-2026-66408&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Dependency on vulnerable third-party component (CWE-1395)&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Known vulnerability in Quectel EG25-G device (CVE-2021-31698)&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-026400</guid>
    </item>
  </channel>
</rss>
