A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home.
The vulnerability impacts SharkNinja robot vacuums and is due to a misconfigured cloud security policy instead of a flaw in the firmware.
Shark robot vacuums are intended for cleaning homes, but it turns out that one was mapping them for outsiders. Security researchers have revealed a significant vulnerability in SharkNinja’s cloud-connected robot vacuums, potentially allowing attackers to remotely access sensitive information, including live camera feeds, home layouts, Wi-Fi credentials, and even execute commands on the affected devices. Alarmingly, the issue remains unresolved despite being responsibly reported to SharkNinja months ago.
How can a vacuum turn into a spy?
The vulnerability was identified by security researcher tokay0, who reverse-engineered a Shark RV2320EDUS robot vacuum. The findings indicate that the device has an AWS IoT certificate allowing communications with other Shark devices in the same AWS region instead of being limited to its own device. This overly permissive cloud policy enables a certificate obtained from one vacuum to connect with numerous others.
Shark RV2320S Shark
If exploited, an attacker could remotely send commands to at-risk vacuums, access live camera feeds, download homeowners' maps, extract Wi-Fi passwords apparently stored in plaintext, and potentially establish a foothold on the victim’s local network. The researcher detected over 1.5 million unique Shark devices in a single AWS region within 24 hours, with approximately 673,000 devices responding in a way that hinted at support for remote command execution. While this does not confirm that all those devices are vulnerable, it suggests that a significant number of products could be affected.
However, the attack is not as straightforward as someone hacking a vacuum via the internet. Initially, an attacker needs physical access to a compatible Shark vacuum to retrieve its embedded certificate through a debugging interface. This drastically increases the difficulty, making the attack more likely to be executed by skilled researchers or determined attackers rather than casual hackers.
The downside is that once such a certificate is obtained, the subsequent steps of the attack can be conducted remotely using SharkNinja’s cloud infrastructure. The researcher pointed out that the fundamental issue lies in the company's cloud-side AWS IoT policy, meaning users cannot resolve it by performing a firmware update. The mitigation measures must be applied by SharkNinja on its servers.
What should Shark owners do?
The researcher mentioned that the vulnerability was first communicated to SharkNinja in March 2026, but there was no patch available at the time of publication. Reports have indicated that a CVE identifier has not been assigned to this issue, and SharkNinja has not yet publicly released a fix.
Until the company resolves the situation, users who do not utilize smart features may want to disconnect their robot vacuum from Wi-Fi or disable remote functionalities to minimize the attack scope. While this serves as a temporary workaround rather than a definitive solution, the ultimate responsibility rests with the manufacturer due to the nature of this cloud-side vulnerability.
Other articles
A vulnerability in the Shark vacuum that hasn't been fixed could jeopardize the security of your smart home.
A recently revealed vulnerability in SharkNinja devices may allow attackers to gain access to robot vacuum cameras, home mapping data, and Wi-Fi passwords due to an unaddressed cloud security issue that impacts millions of units.
