Robot Vacuums: Control Lost, Data Leaked

Robot Vacuums: Control Lost, Data Leaked

Redaksiya · Texnologiya ·

A user who accidentally modified their device to enable control via a PlayStation controller has gained access to over 6700 robot vacuums. The security vulnerability exposed floor plans and live video feeds.

Redaksiya reports that this incident occurred after a technician created an application to control their device with a PlayStation controller. According to The Verge, this problem allowed the application to access precise floor plans, live camera and microphone feeds, and even remotely control affected devices.

This situation was accidentally discovered by AI strategist Sammy Adoufal. He used Claude Code to reverse-engineer the protocol used to connect to DJI Romo's servers. However, instead of gaining access only to his own device, he took control of approximately 6700 robot vacuums worldwide. Adoufal stated that he did not access DJI systems in any way. He noted that he only obtained the personal token for his own Romo vacuum. In a statement to The Verge, he said, "I didn't break any rules, I didn't bypass anything, I didn't crack anything, I didn't force anything." Because of this, he was able to access live servers worldwide, including in the US, Europe, and even China.

Fortunately, he did not use this information to exploit others' privacy. He contacted DJI about the problem, and the company eventually resolved it with several updates that did not require any action from the user. Nevertheless, the AI strategist points out that there are several outstanding issues that need to be addressed. These include the ability for DJI Romo to stream video feeds without a security PIN and another undisclosed problem. More importantly, Adoufal notes that the root of the problem is not the encryption used by the robot vacuum when communicating with the server, but rather that all data is stored in plain text and can be easily read by anyone who gains access to the server.

This is not the first incident of a robot vacuum not properly managing the data it collects. Last year, an engineer discovered that the iLife A11 smart vacuum was continuously sending logs and telemetry data to the manufacturer. When he prevented this data from being sent back over his network, the manufacturer sent a code that remotely disabled the device. With a little modification and ingenuity, he was able to fully restore and use his device locally, proving that a robot vacuum does not need to be cloud-connected 24/7 to function as intended.

Many users purchase and install IoT smart devices in their homes due to the convenience they offer. However, incidents like these show how dangerous they can be, with technicians accidentally gaining access to these systems. This raises several red flags, with security researchers noting that if ordinary individuals can stumble upon the private data of thousands of people through these devices, then a coordinated attack could cause far more damage than anticipated.