Particle.news
Download on the App Store

DJI Patches Romo Robot Vacuum Data Flaw After Researcher Accesses Thousands of Devices

DJI says early‑February updates to its Home app fixed a server‑side permission flaw exposed by a researcher.

Overview

  • Programmer Sammy Azdoufal reports he accessed data from roughly 7,000 Romo vacuums in 24 countries while experimenting with PlayStation controller integration.
  • He says he could view detailed home maps, device status, and approximate locations and in some cases see or hear live feeds, gathering more than 100,000 messages.
  • The Verge confirmed he could retrieve a precise floor plan and observe activity from a test unit but found no ability to control the device or access live audio or video.
  • DJI states it identified a DJI Home vulnerability in late January and deployed two automatic fixes in early February, with no user action required.
  • The company characterizes unauthorized video access as extremely rare, while security experts say the episode highlights persistent weaknesses in consumer IoT security.