--- Source 2 --- Shark Vacuum Security Flaw Exposed Home Layouts, Wi-Fi Passwords
A security flaw in Shark ION Robot Vacuums could have allowed attackers to access sensitive user data, including home layouts, Wi-Fi network names and passwords, and even live camera feeds. The vulnerability, discovered by researchers at Checkmarx, affected models with camera functionality.
The flaw stemmed from a misconfiguration in the robot vacuum's cloud communication. Researchers found that by manipulating requests sent to Shark's servers, they could gain unauthorized access to data associated with a user's vacuum cleaner. This included the detailed maps of a user's home that the vacuum creates, which could reveal room layouts and even the location of valuable items. More critically, the vulnerability exposed the user's Wi-Fi SSID and password, potentially allowing an attacker to gain access to the entire home network. For models equipped with cameras, the flaw also presented a risk of unauthorized access to the live video feed.
Checkmarx reported the vulnerability to SharkNinja, the manufacturer, who has since released a patch to address the issue. Users are advised to ensure their Shark ION Robot Vacuums are updated to the latest firmware version. The researchers emphasized the growing security risks associated with smart home devices, particularly those with cameras and network connectivity, highlighting the importance of secure development practices and prompt patching by manufacturers.






