Tech Radar disclosed that a hobbyist accidentally gained access to thousands of DJI Romo vacuums worldwide, exposing sensitive data including floor plans and live video feeds online. The vulnerability stemmed from unprotected server storage, despite intact communication encryption.An AI strategist, Sammy Azdoufal, discovered the issue while reverse-engineering his own DJI Romo vacuum. While attempting to control his device with a PlayStation controller, he received private tokens for over 6,700 other vacuums across the United States, Europe, and China. The core problem was that device data was stored in plain text on the server, allowing unauthorized access to floor plans, live video feeds, and microphone input. Although DJI has issued updates to address some issues, vulnerabilities remain, including the ability to stream video without a security PIN.The accidental exposure of sensitive personal information raises concerns about both unintended access and potential targeted attacks. It underscores the need for manufacturers to implement stronger server-side data storage and access control measures. Consumers should remain aware of potential privacy risks, even with minor device misconfigurations or design flaws, and consider network security measures like firewalls and endpoint protection.Source: Tech Radar
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




