Search...

A simple attack method provided access to thousands of DJI Romo robovacs

A simple attack method provided access to thousands of DJI Romo robovacs

A serious security issue affecting DJI’s first robot vacuum, the DJI Romo, reportedly enabled a user to inadvertently gain access to data from thousands of devices worldwide. According to available information, when Sammy Azdoufal connected a custom application - built to remotely operate his newly purchased Romo using a PlayStation 5 controller - to DJI’s cloud infrastructure, a backend misconfiguration caused his authentication credentials to be accepted across approximately 7,000 active devices over 24 countries.

While developing the homebrew remote-control app, Azdoufal used an AI coding assistant (Claude Code) to reverse-engineer how the Romo communicates with DJI’s servers and to extract the authentication token associated with his own device. However, the same token was reportedly sufficient to access other Romo units operating on the same infrastructure. As a result, he was able to observe device status information, telemetry, and, in some cases, functions considered sensitive from a privacy perspective.

This flaw enabled access to live camera feeds, audio captured via on-device microphones, and the generation of 2D floor plans of the environments in which the robots were operating. In addition, device IP addresses were reportedly accessible, allowing approximate geographic location estimates. It is also noted that using only a 14-digit serial number, it was possible to identify a separate device, confirm the room it was cleaning and its battery level, and observe a remotely generated floor plan. DJI Power portable power stations operating on the same infrastructure were visible and transmitted diagnostic and status data.

From a technical standpoint, the root cause has been described as a backend permission validation issue, compounded by insufficient topic-level access controls (ACLs) within an MQTT-based messaging environment. Under these conditions, a valid token issued for one device could be used to access message traffic and data associated with other devices. Security specialists note that such architectural failures are particularly high-risk in smart home ecosystems, where sensors such as cameras and microphones can expose highly sensitive in-home information.

DJI has stated that the issue was remediated via a two-stage update: an initial patch deployed on February 8, followed by a supplementary update completed on The company also noted that the fix was deployed automatically and required no action from users. Nonetheless, additional concerns have been raised, including reports of a separate risk involving access to a device’s camera stream without requiring the security PIN. Another issue has been assessed as more severe from a security and privacy standpoint, with details not publicly disclosed. DJI has indicated that it expects to address this within the coming weeks.

The incident underscores longstanding concerns that internet-connected smart home devices - particularly those equipped with cameras and microphones - remain attractive targets for misuse. Experts further warn that the growing availability of AI-powered coding tools is lowering the barrier to reverse engineering and exploit development, potentially increasing both the frequency and impact of similar vulnerabilities. Against this backdrop, manufacturers are urged to implement stricter access control and authorization mechanisms in cloud services, while users are advised to keep firmware up to date and, where feasible, minimize the use of privacy-sensitive features.

References:

© 2011-2026 All rights reserved