Thousands of DJI vacuums hacked across 24 countries, remote access

A developer stumbled into DJI's network of robot vacuums and gained remote control access to thousands of devices across 24 countries.

Thousands of DJI vacuums hacked across 24 countries, remote access
Comment IconFacebook IconX IconReddit Icon
Tech and Science Editor
Published
1 minute & 15 seconds read time
TL;DR: A security researcher accessed 6,700 DJI robot vacuums across 24 countries, remotely viewing cameras, floor plans, and IP addresses by exploiting a network vulnerability. After reporting the issue, DJI promptly patched the security flaw to protect user privacy and prevent unauthorized device control.

A developer who purchased an expensive DJI robot vacuum has managed to gain access to thousands of DJI vacuums across 24 countries, with the developer being able to remotely view through their cameras, harvest floor plans, IP addresses, and more.

Thousands of DJI vacuums hacked across 24 countries, remote access 295

Sammy Azdoufal, an AI strategist at a property management company, has shown The Verge how they managed to gain access to DJI's network of robot vacuums, and it started with the purchase of his own Romo robot vacuum. Azdoufal wondered if it would be able to control the Romo vacuum with a PS5 controller. Azdoufal noticed the Romo vacuum offered remote control through the smartphone app.

Azdoufal decided to write his own app with Claude Code, and after verifying his own vacuum on the network, he realized he had actually gained access to approximately 6,700 devices across 24 countries. Azdoufal said the background access was severe as he was able to see through the cameras of the devices, steer them, and see sensitive metadata such as serial numbers, IP addresses, and even floor plans the vacuums tracked. Additionally, by entering a 14-digit code, he was even able to bypass any PIN on the devices.

Thousands of DJI vacuums hacked across 24 countries, remote access 202602242

The security hole has since been plugged by DJI, as Azdoufal notified the company of his seemingly unfettered access to the network shortly after he made the discovery. Notably, DJI said it was already in the process of rolling out a fix for the issue, but it had yet to deploy it across the network.

News Sources:techspot.com and theverge.com

Tech and Science Editor

Email IconX IconLinkedIn Icon

Jak joined TweakTown in 2017 and has since reviewed 100s of new tech products and kept us informed daily on the latest science, space, and artificial intelligence news. Jak's love for science, space, and technology, and, more specifically, PC gaming, began at 10 years old. It was the day his dad showed him how to play Age of Empires on an old Compaq PC. Ever since that day, Jak fell in love with games and the progression of the technology industry in all its forms.

Follow TweakTown on Google News
Newsletter Subscription