Software Engineer Gains Unintentional Control of Thousands of DJI RoboVacuums
A security flaw in the newly released DJI RoboVacuums has allowed a Spanish software engineer to remotely access and control over 7,000 devices worldwide, raising serious privacy and security concerns. The incident, first reported by Dutch media outlets de Volkskrant and Hart van Nederland, highlights vulnerabilities in the increasingly connected world of smart home devices. The engineer, whose name has not been publicly released, discovered the flaw while researching the security protocols of the DJI RoboVacuums.
The DJI RoboVacuums, the company’s first foray into the robotic vacuum cleaner market, boast advanced features including obstacle detection inspired by DJI’s drone technology, a powerful 25,000 Pa suction and an intelligent self-cleaning system. Available in three models – the ROMO S (€1299), ROMO A (€1599), and ROMO P (€1899) – the vacuums utilize a dual fisheye camera system with 3D recognition for navigation. However, this sophisticated technology appears to have inadvertently created a significant security loophole. The engineer was able to gain access to the devices through a vulnerability in the system’s cloud connection, allowing him to view live camera feeds and potentially control the vacuums’ movements.
Security Flaw Exploited: Access to Camera Feeds and Potential Control
According to reports, the engineer was able to access the live camera feeds of over 6,700 DJI RoboVacuums, and in some cases, control their functions. Clickx reported that the engineer was able to view the interiors of homes and potentially interact with the environment through the robot vacuums. While the engineer has stated he had no malicious intent and promptly reported the vulnerability to DJI, the incident underscores the risks associated with connected devices and the importance of robust security measures.
The DJI RoboVacuums’ all-in-one dock features automatic suction, hot water self-cleaning, and a 2.4L disposable dust bag. The system also includes separate tanks for fresh and dirty water (4L and 3.2L respectively), and a hot air drying function. The ROMO P model includes additional features such as an automatic floor deodorizer and a UV lamp for dust bag disinfection. However, these advanced features appear to have come at the cost of security, as the engineer was able to exploit a weakness in the system’s authentication protocols.
DJI’s Response and the Broader Implications for Smart Home Security
As of February 25, 2026, DJI has not issued a comprehensive public statement addressing the specific security breach. However, the company is reportedly working on a software update to patch the vulnerability. The incident has sparked a wider debate about the security of smart home devices and the potential for unauthorized access to sensitive data. Experts warn that as more and more devices become connected to the internet, the risk of similar breaches will only increase.
“This incident is a wake-up call for both manufacturers and consumers,” says cybersecurity analyst Dr. Anya Sharma. “Manufacturers need to prioritize security from the design phase and implement robust testing procedures. Consumers need to be aware of the risks and take steps to protect their privacy, such as changing default passwords and keeping their devices’ software up to date.”
The DJI RoboVacuums utilize a cartridge system for cleaning solutions, with sealed disposable cartridges that are not refillable. The base tray features four high-pressure nozzles for self-rinsing, and the system automatically cleans itself after each cycle. While these features contribute to the convenience of the device, they also add to the complexity of the system, potentially creating more opportunities for security vulnerabilities. The HyperSuction technology, boasting 25,000 Pa of suction power, is a key selling point, but it’s the underlying software and network connections that have proven to be the weak link.
The Role of the Camera System in the Breach
The dual fisheye camera system, designed for advanced navigation and obstacle avoidance, appears to be central to the security breach. The cameras provide a live feed of the vacuum’s surroundings, which the engineer was able to access remotely. This raises concerns about the potential for unauthorized surveillance and the violation of privacy. While DJI has not confirmed the extent of the data accessed by the engineer, the possibility of sensitive information being compromised is a serious concern.
The ROMO series, as described on the official DJI website, combines cutting-edge perception and electromechanical technology inspired by their flagship drones. The company emphasizes the precision and intelligence of the device, but the recent security breach casts a shadow over these claims. The incident highlights the need for a more holistic approach to security, one that considers not only the physical capabilities of the device but also the vulnerabilities of its software and network connections.
What In other words for Consumers and the Future of Smart Home Devices
This incident serves as a stark reminder that convenience and connectivity come with inherent risks. Consumers should be cautious about the data they share with smart home devices and take steps to protect their privacy. This includes regularly updating software, using strong passwords, and being aware of the potential for unauthorized access. The incident also underscores the need for greater transparency from manufacturers regarding the security features of their products.
The potential for remote control of the RoboVacuums, while not confirmed to have been fully exploited, raises even more alarming possibilities. Imagine a scenario where a malicious actor could use a compromised robot vacuum to map a home’s layout, identify valuable possessions, or even create a pathway for a burglary. While this remains a hypothetical threat, it highlights the importance of addressing security vulnerabilities before they can be exploited for criminal purposes.
DJI’s response to this breach will be critical in restoring consumer trust. A swift and transparent resolution, including a detailed explanation of the vulnerability and the steps taken to address it, will be essential. The company may also face regulatory scrutiny, as data privacy laws are becoming increasingly stringent around the world.
The future of smart home devices hinges on the ability of manufacturers to prioritize security and protect consumer privacy. Incidents like this one serve as a valuable lesson, demonstrating that innovation must be balanced with a commitment to responsible technology development. As the number of connected devices continues to grow, the stakes will only get higher.
The next step in this developing story will be the release of DJI’s software update and a more detailed explanation of the security flaw. Consumers should monitor DJI’s official website and news sources for updates. We encourage readers to share their thoughts and concerns about smart home security in the comments below.
Keep reading