mimile
mimile.ai
Back to feed
This event is part of a larger story
Массовые утечки и атаки: июль 2026 года
Read briefing

Shark robot vacuum flaw exposes cameras, Wi-Fi passwords

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Shark robot vacuum flaw exposes cameras, Wi-Fi passwords

A security researcher discovered that Shark robot vacuums contain an unpatched AWS IoT policy flaw allowing a compromised device to access cameras, home maps, and Wi-Fi passwords of other vacuums in the same region. The flaw affects potentially hundreds of thousands of devices, with 673,816 units observed responding to remote commands during a 24-hour test.

The Vulnerability

Researcher tokay0 analyzed a Shark RV2320EDUS vacuum and found its embedded AWS IoT certificate could publish and subscribe to topics for any Shark device in the same AWS Region, not just itself. AWS Regions are isolated geographic data center clusters; there are 39 worldwide. The overly permissive MQTT policy allows a stolen certificate to access other vacuums' device shadows, which store configuration and commands.

Potential Impact

An attacker with cloud access could view live camera feeds, steal Wi-Fi passwords stored in plaintext, and copy home maps revealing room layouts. During a 24-hour period in one AWS Region, the researcher observed 1,517,605 unique Shark serial numbers, with 673,816 devices (44%) supporting remote command execution. The initial compromise requires physical access to extract the certificate, but subsequent abuse is remote.

Industry Context

Similar vulnerabilities have affected other smart vacuums; Malwarebytes previously reported Ecovacs models being hijacked to play obscene messages and spy on users. The researcher noted it is difficult to estimate the exact number of affected devices but concluded a very large number of SharkNinja IoT devices are vulnerable.

What's Next

SharkNinja has not yet released a patch for the flaw. It remains unclear whether the company will issue a firmware update or require hardware changes to fix the overly permissive certificate policy.

1 source

Shark robot vacuum flaw exposes cameras, Wi-Fi passwords