Millions of Shark Robot Vacuums Exposed to Remote Code Execution via a SharkNinja Cloud Flaw
Robot vacuums have long roamed our homes unattended. Yet on certain Shark models, the cleaning came bundled with an unnoticed doorway for strangers. A security researcher uncovered a critical vulnerability that allows commands to be executed on the devices over the internet, their movement to be controlled, and the data they collect to be accessed.
A Misconfigured Cloud at the Heart of the Flaw
The problem lies in the SharkNinja cloud system, through which the vacuums exchange messages with Amazon servers. Each unit uses its own certificate and private key. However, for a subset of devices, the access permissions were configured incorrectly. One vacuum’s certificate could subscribe to the messages of other units and send them commands.
The Exec_Command Weakness
During his examination, the researcher discovered an Exec_Command function in the software. The vacuum accepted a string received from the cloud and passed it to the system shell without adequate validation. As a result, the owner of one vulnerable device could execute arbitrary code on another vacuum, knowing only its serial number.
The researcher confirmed the attack on two Shark models he owned, the RV2320EDUS and the AV1102ARUS. The first device’s certificate let him dispatch a command to the second and run a foreign file on it. Testing further showed that the vulnerability worked across different models.
Beyond Cleaning: Cameras, Maps, and Wi-Fi Passwords
The consequences reach well beyond starting and stopping a cleaning cycle. Some vacuums carry a camera and store a map of the home, the household Wi-Fi password in plaintext, and other service data. The author of the study was able to pull the camera feed, remotely control the motors, and drive the device around the house.
The Scale of Exposure
Over a single day of monitoring one cloud node, the researcher registered more than 1.5 million unique devices. At least 673,816 of them returned responses confirming support for the dangerous command. This figure covers only one Amazon region, so the total number of vulnerable units could be considerably higher.
Configurations, meanwhile, vary from model to model. The AV1102ARUS certificate could not view others’ messages, whereas newer RV2320EDUS firmware received excessively broad permissions. In the author’s view, the flawed access policy emerged later and spread across most connected Shark devices.
Disclosure Met With Silence
SharkNinja was notified of the problem in March 2026. The company confirmed receipt of the materials. Yet more than four months later, it has released no fix and named no firm date for one. The researcher also approached MITRE to register the vulnerability, though no CVE identifier has been assigned so far. Notably, the author declined to publish the technical tools for carrying out the attack, since the vulnerability remains open.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.