Shark Robot Vacuums Expose Cameras and Wi-Fi

20.07.2026 3 minutes Author: Newsman

Shark robot vacuums may contain a critical vulnerability that could allow attackers to turn the devices into surveillance tools. According to a cybersecurity researcher, the issue remains unpatched more than three months after it was reported to the manufacturer.

According to a cybersecurity researcher known as Tokay0, the vulnerability could allow attackers to remotely access a robot vacuum, view images from its onboard camera, steal home Wi-Fi passwords, and even copy the home’s floor map.

“Millions of Shark vacuums are currently vulnerable to remote code execution. This critical flaw effectively turns the cameras inside Shark robot vacuums into hackable surveillance devices inside people’s homes,” the researcher said.

The issue stems from a flaw in the AWS IoT policies that Shark robot vacuums use to communicate with the company’s cloud infrastructure. While examining a Shark RV2320EDUS, Tokay0 discovered an embedded AWS IoT certificate. Because of improperly configured access policies, a stolen certificate from one device could be used to communicate with other Shark vacuums registered in the same AWS region.

AWS divides its cloud infrastructure into 39 separate geographic regions. As a result, a certificate taken from a device registered in the US West (Northern California) region would not work for devices registered in the Europe (London) region. However, this does not eliminate the risk, as an attacker could simply obtain a device registered in the target region and use its certificate.

According to Tokay0, around 673,000 SharkNinja devices were observed in a single AWS region within 24 hours, while more than 1.5 million unique devices were identified overall. If similar numbers apply across other AWS regions, millions of Shark robot vacuums could potentially be affected.

“This vulnerability impacts a very large number of SharkNinja IoT devices. Although devices can only authenticate within the AWS region tied to their certificates, an attacker could easily acquire devices registered in specific regions and use them to compromise other devices in those same regions,” Tokay0 explained.

The research primarily focused on the Shark RV2320EDUS and AV1102ARUS models, but the researcher believes other Shark robot vacuums may also be affected. SharkNinja sold more than 28 million devices worldwide last year.

Tokay0 says he reported the vulnerability to the company in March 2026. According to him, SharkNinja responded only with a brief statement saying it was working on a fix before communication stopped.

“SharkNinja basically replied with a vague ‘we’re working on it.’ After several follow-up attempts asking for more details that went unanswered, I gave up,” the researcher said.

After the standard 90-day responsible disclosure period expired, Tokay0 published the technical details of the vulnerability.

The attack does have one significant limitation. An attacker must first obtain physical access to a Shark robot vacuum, disassemble it, and extract its AWS certificate from the device’s memory. As a result, exploiting the vulnerability is relatively complex and requires technical expertise.

SharkNinja is a U.S.-based company headquartered in Needham, Massachusetts. It manufactures robot vacuums, air purifiers, kitchen appliances, and other home devices, generating more than $6.3 billion in annual revenue.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.