news.mlab.sh
Back to the feed
vulnerability

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

Critical
Summary

A researcher discovered a critical vulnerability in Shark robot vacuums due to a flawed certificate policy on Amazon's AWS cloud platform. Attackers can exploit this to gain remote control of vacuums across an entire AWS region by leveraging a wildcard certificate policy. Despite contacting SharkNinja in March, the company has not yet released a patch, and the vulnerability remains unaddressed, leaving millions of vacuums potentially vulnerable. The only mitigation for users is to disconnect the vacuum from Wi-Fi, effectively disabling smart features.

A researcher, known as tokay0, has identified a critical vulnerability in Shark robot vacuums, exposing a significant number of devices to remote control attacks. The flaw stems from a misconfigured certificate policy on Amazon's AWS cloud platform. Specifically, the certificate policy attached to the device’s certificate was not scoped correctly, allowing an attacker to wildcard-subscribe to a broad range of devices within an AWS region.

By obtaining a certificate from a vulnerable Shark RV2320EDUS robot vacuum, an attacker can then use that certificate to execute commands on other Shark vacuums, including accessing the camera feed, driving the robot, reading the house map, and stealing the Wi-Fi password. The researcher discovered that 1,517,605 unique Shark serial numbers emitted an Exec_Response within a 24-hour period, indicating that a substantial portion of devices were actively responding to the command handler.

SharkNinja acknowledged receiving the report in March, but as of Thursday, July 15th, the company had not yet released a patch. The researcher contacted MITRE for a CVE ID, but no identifier was assigned. The vulnerability is not a firmware issue; the fix resides on SharkNinja’s AWS account, requiring a server-side policy update using CreatePolicyVersion and the setAsDefault flag.

Users are advised to disconnect their vacuums from Wi-Fi to disable remote control and scheduling features, effectively reverting the device to its basic vacuum functionality. The researcher withheld his scripts while the vulnerability remained active, and he noted that SharkNinja’s connected smart grills and wireless meat probes are likely vulnerable as well, given the company’s published vulnerability disclosure policy promising regular updates.

SharkNinja has not yet released a patch and has not provided a confirmed completion date for the fix.

Read the full article at The Hacker News