Shark vacuum robots have an unpatched flaw that could let attackers access cameras, WiFi passwords, and home maps, researcher claims.

Researcher Tokay0 says SharkNinja failed to fix the issue more than 90 days after private disclosure.

The flaw involves AWS IoT certificates, with 673,000 exposed SharkNinja devices observed in one AWS region.

  • SmoothLiquidation@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    Would this make them useful to side load your own firmware to them? This “exploit” could make these into a hobbyist’s dream