Shark vacuum robots have an unpatched flaw that could let attackers access cameras, WiFi passwords, and home maps, researcher claims.

Researcher Tokay0 says SharkNinja failed to fix the issue more than 90 days after private disclosure.

The flaw involves AWS IoT certificates, with 673,000 exposed SharkNinja devices observed in one AWS region.

  • Scipitie@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    To get to the certificate with which you THEN can attack devices remotely. I.e. the attacker needs one device. And the skill to extract the certificate and the willingness to abuse it.

    One of each and then the 613k devices in the tested region are exposed.