Shark vacuum robots have an unpatched flaw that could let attackers access cameras, WiFi passwords, and home maps, researcher claims.

Researcher Tokay0 says SharkNinja failed to fix the issue more than 90 days after private disclosure.

The flaw involves AWS IoT certificates, with 673,000 exposed SharkNinja devices observed in one AWS region.

  • Q The Misanthrope @startrek.website
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    2 days ago

    Not shocked. I bought one four years ago, had a ton of issues. After many attempts they send me a new one with the exact same issues. So I have two and neither one works. I’d rather clean the floors myself than fight it.

    Their software is garbage, their hardware is garbage.

    Anyway based on that experience, I have no doubt their software is full of exploits and issues.

    Not to reduce the impact of this article but it does point out:

    Attackers need physical device access first, limiting the risk mainly to technically skilled people with a Shark device.

    • SmoothLiquidation@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      Would this make them useful to side load your own firmware to them? This “exploit” could make these into a hobbyist’s dream

    • Scipitie@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      To get to the certificate with which you THEN can attack devices remotely. I.e. the attacker needs one device. And the skill to extract the certificate and the willingness to abuse it.

      One of each and then the 613k devices in the tested region are exposed.