logo

Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw

ID: 68ee0a7a-fc15-5676-a106-45e7be5ea028

STIX ID: report--68ee0a7a-fc15-5676-a106-45e7be5ea028

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Divya

...
...

A researcher disclosed a critical remote code execution vulnerability in internet-connected Shark robot vacuums stemming from overly permissive AWS IoT MQTT policies and an embedded firmware command-execution feature. By extracting a device-specific AWS certificate from an affected unit, the researcher could subscribe/publish to wildcard MQTT topics across devices and trigger arbitrary high-privilege commands (proven across different models), potentially exposing live camera feeds, home mapping data, and plaintext Wi‑Fi credentials; the researcher observed ~1.52M unique devices in one AWS region and ~673k indicating support for the command-exec capability. SharkNinja was notified on March 11 and the issue was publicly disclosed July 13 with no confirmed patch at disclosure; recommended mitigations include restricting IoT policies, reprovisioning/revoking certificates, and isolating IoT devices on separate networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.