Shark Vacuum RCE Flaw Lets Attackers Remotely Control Cameras and Motors
ID: 3f22c2e5-8d6a-5544-ae19-78f6f36fab74
STIX ID: report--3f22c2e5-8d6a-5544-ae19-78f6f36fab74
Feed Name: Cyber Press
A critical RCE and privacy vulnerability was discovered in SharkNinja robot vacuums stemming from misconfigured AWS IoT Core policies and device certificates that permit wildcard MQTT subscriptions and delivery of arbitrary shell commands via an 'Exec_Command' field; the researcher demonstrated cross-model exploitation, observed ~10.5M messages across 1.5M device serials and estimated ~673K vulnerable devices in one region, enabling camera hijacking, motor control, and extraction of Wi‑Fi credentials, and the issue remained unpatched at the time of disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
