Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw
ID: 68ee0a7a-fc15-5676-a106-45e7be5ea028
STIX ID: report--68ee0a7a-fc15-5676-a106-45e7be5ea028
Feed Name: GBHackers
A researcher disclosed a critical remote code execution vulnerability in internet-connected Shark robot vacuums stemming from overly permissive AWS IoT MQTT policies and an embedded firmware command-execution feature. By extracting a device-specific AWS certificate from an affected unit, the researcher could subscribe/publish to wildcard MQTT topics across devices and trigger arbitrary high-privilege commands (proven across different models), potentially exposing live camera feeds, home mapping data, and plaintext Wi‑Fi credentials; the researcher observed ~1.52M unique devices in one AWS region and ~673k indicating support for the command-exec capability. SharkNinja was notified on March 11 and the issue was publicly disclosed July 13 with no confirmed patch at disclosure; recommended mitigations include restricting IoT policies, reprovisioning/revoking certificates, and isolating IoT devices on separate networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
