News (EN)

Security flaw exposes cameras and maps of 7,000 DJI Romo robot vacuum cleaners in 24 countries

Robô aspirador DJI Rom - Robert Way/ Shutterstock.com
Photo: Robô aspirador DJI Rom - Robert Way/ Shutterstock.com
Share

A Spanish software engineer discovered a serious security vulnerability in the DJI Romo robot vacuum cleaner, launched in February 2026 by the Chinese company. Sammy Azdoufal only intended to create a custom application to control your own device with a PlayStation 5 controller. Durante the experiment, he accessed data from approximately 7 thousand units in at least 24 countries. The flaw allowed viewing of live camera feeds, microphone audio, home floor plans, and approximate locations based on IP addresses.

The incident occurred because the authentication token extracted from Azdoufal’s device served as a master key on DJI’s servers. Ele did not need to break into systems or use brute force. The MQTT protocol, used for communication between robots and the cloud, did not correctly validate permissions per device. Isso resulted in unauthorized access to sensitive information of thousands of users without their knowledge.

DJI confirmed the existence of the issue upon notification. The company implemented corrections in two automatic updates at the beginning of February 2026. Essas updates restricted unauthorized access and were applied without the need for intervention from device owners. The flaw mainly affected MQTT-based communication between devices and the cloud server.

Discovery during home experiment

Sammy Azdoufal used Anthropic’s AI tool Claude to analyze Romo’s communication protocol. Ele developed a custom client that mapped PS5 controller commands to robot movements. The goal was to make the operation more fun, similar to a game.

During testing, the application connected to the DJI server. Instead of receiving data just from your Romo, it obtained information from thousands of other devices. Azdoufal was able to remotely control the devices, check battery levels and observe what the cameras captured in real time.

He demonstrated real-time access for journalists. In just a few minutes, it collected more than 100,000 telemetry messages sent by robots every few seconds. The data included cleaning status, detected obstacles, and maps generated by the sensors.

How the technical loophole worked

The MQTT protocol allows devices to publish and subscribe to message topics in a lightweight way. In the case of Romo, the devices sent constant packets with serial number, status and visual data. The server accepted broad subscriptions without restrictions per individual token.

Authentication did not tie the token to a specific device. Qualquer valid token allowed broad access. Isso displayed not only the video and audio, but also detailed floor plans of the residences.

Cybersecurity experts point out that similar flaws occur in IoT devices when cloud access controls are insufficient. The incident reinforces risks in connected products that map indoor environments.

Robo aspirador
Robot vacuum cleaner – Yuganov Konstantin/ shutterstock.com

DJI response and applied fixes

DJI started internal corrections in January 2026. Após contacted Azdoufal and press outlets, the company accelerated the updates. Duas patches were automatically sent on February 8th and 10th.

The company stated that the problem was resolved and that remediation was already underway before public disclosure. A spokeswoman explained that the vulnerability involved validating permissions on the backend.

Azdoufal noted that some minor issues persisted initially, such as accessing video streams without a security PIN. DJI has promised to address these additional points in future updates.

Risks for smart device users

Robot vacuums with cameras and microphones represent potential targets in connected home networks. Unauthorized Acesso can expose daily routines, home layouts and private conversations. Previous Casos with other brands have shown similar abuse.

The incident highlights the need for strict authentication in IoT protocols. Tokens must be scoped by device and limited subscriptions. Fabricantes need to test wildcard topics and permissions validations.

Users must maintain updated firmware and segment networks for smart devices. Simple Medidas reduces exposure in connected ecosystems.

Impact on the home robot market

The DJI Romo has entered the robot vacuum segment with advanced mapping and camera features. The failure occurred shortly after the global launch. Isso may affect trust in the brand’s products, known for drones.

Companies in the sector face increasing pressure for security. Incidentes state that connectivity convenience requires rigorous monitoring. The case serves as a warning for the entire domestic IoT industry.

Azdoufal shared his code for gamepad control after the fixes. Ele emphasized that it did not explore the data and reported the problem immediately.

Share

More news in News (EN)

See more