<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 14:14:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-350754</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-350754</link>
      <description>EUVD-2026-350754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-350754</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66409</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66409</link>
      <description>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.&#13;
The password may be analyzed and obtained to connect to the access point of an affected robot.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.&#13;
The password may be analyzed and obtained to connect to the access point of an affected robot.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66409</guid>
    </item>
    <item>
      <title>GHSA-829w-c4jv-vqj4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-829w-c4jv-vqj4</link>
      <description>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obtained to connect to the access point of an affected robot.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obtained to connect to the access point of an affected robot.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-829w-c4jv-vqj4</guid>
    </item>
    <item>
      <title>jvndb-2026-026400</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-026400</link>
      <description>&lt;p&gt;Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;telnet server remains enabled (CWE-489) - CVE-2026-66405&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Weak password for root account (CWE-1391) - CVE-2026-66408&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Dependency on vulnerable third-party component (CWE-1395)&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Known vulnerability in Quectel EG25-G device (CVE-2021-31698)&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;telnet server remains enabled (CWE-489) - CVE-2026-66405&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Weak password for root account (CWE-1391) - CVE-2026-66408&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Dependency on vulnerable third-party component (CWE-1395)&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Known vulnerability in Quectel EG25-G device (CVE-2021-31698)&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-026400</guid>
    </item>
  </channel>
</rss>
