DJI Romo Robot Vacuum Security Vulnerabilities

Reference TimelineLast updated
SUMMARY

DJI paid security researcher Sammy Azdoufal a $30,000 bug bounty on March 7, 2026, for discovering a critical flaw in its Romo robot vacuums that exposed live camera feeds, microphone audio, and home mapping data from approximately 7,000 devices. As of June 4, 2026, primary vulnerabilities have been patched, but secondary issues, including a PIN bypass for camera access, remain unaddressed, with DJI promising further fixes. The vulnerability also affected DJI Power portable battery stations due to authentication tokens not being scoped to individual devices, raising ongoing concerns about data security and potential data transmission to China. DJI is using findings from a recent independent cybersecurity audit of its drone systems, which found no critical vulnerabilities, in its appeal against the FCC's Covered List designation, despite the Romo flaw.

Timeline

Want updates on this thread?

Track this story

Timeline of developments

June 2026 1 developments

  1. DJI Drone Security Audit Finds No Critical Flaws Amidst Romo Vacuum Vulnerability Scrutiny

    An independent cybersecurity audit of DJI's drone systems, conducted between October 2025 and March 2026, found no critical, high, or medium-risk vulnerabilities. DJI is using these findings in its appeal against the FCC's Covered List designation, despite a recent security flaw in its Romo robot vacuum.

March 2026 2 developments

  1. DJI Romo robot vacuum flaw exposed camera feeds, audio, and home mapping data

    A significant security flaw in the DJI Romo robot vacuum allowed unauthorized access to live camera feeds, microphone audio, and home mapping data for thousands of devices. The vulnerability, which also affected DJI Power portable battery stations, stemmed from authentication tokens not being scoped to individual devices. DJI faces ongoing scrutiny regarding data security and privacy, with concerns about potential data transmission to China.

  2. DJI pays $30,000 bug bounty to researcher for critical Romo robot vacuum flaw

    DJI has paid a $30,000 bug bounty to security researcher Sammy Azdoufal for discovering a critical flaw in its Romo robot vacuums. The vulnerability exposed approximately 7,000 devices to potential remote access, including cameras. Azdoufal discovered the flaw accidentally while attempting to control his own Romo vacuum.

February 2026 11 developments

  1. DJI promises further fixes for unaddressed secondary vulnerabilities, including PIN bypass

    As of the current date, primary vulnerabilities are patched, but secondary issues, including a PIN bypass for camera access, remain unaddressed, with DJI promising further fixes [1, 2, 12].

  2. DJI to address remaining security issues "within weeks"

    DJI indicates that remaining security issues will be addressed "within weeks" [3, 12].

  3. TipRanks and Android Headlines report on DJI privacy implications and reputation damage

    Further reporting by outlets like TipRanks and Android Headlines emphasizes the privacy implications and the potential damage to DJI's reputation, especially given previous security scrutiny [3, 4].

  4. Vulnerability allowed access to Romo vacuums and DJI Power battery stations

    It is reported that the vulnerability allowed access not only to Romo vacuums but also to DJI Power portable battery stations sharing the same infrastructure [1, 12].

  5. Tech Outlets Analyze DJI Romo Vulnerability, Detail MQTT Broker Access Controls

    Multiple technology news outlets, including Android Authority and Malwarebytes, publish in-depth analyses of the DJI Romo vulnerability, explaining the technical cause (MQTT broker access controls) and the extent of data exposure [1, 2, 8, 12].

  6. TechBriefly Reports DJI Patch Deployed, Azdoufal Claims Remaining Vulnerabilities

    TechBriefly reports on DJI's patch deployment but notes Azdoufal's claim that secondary vulnerabilities remain unaddressed [5].

  7. DJI Patches Security Issue, Claims No Malicious Exploitation

    DJI states that the security issue has been patched, with remediation deployed in two updates, and claims no evidence of malicious exploitation [5, 9].

  8. The Verge Reports DJI Romo Vulnerability Discovered by Sammy Azdoufal

    The Verge publishes its initial report detailing the DJI Romo vulnerability, highlighting Sammy Azdoufal's discovery and the potential for remote access to approximately 7,000 units globally [7, 9, 11].

  9. DJI deploys second patch, completes initial fix for Romo platform wildcard access issue

    DJI deploys a second automatic patch, completing the initial fix for the main wildcard access issue affecting the Romo platform [1, 4, 5, 9, 11].

  10. DJI deploys first automatic patch for Romo robot vacuum vulnerability

    DJI deploys the first automatic patch to address the primary vulnerability in its Romo robot vacuums, indicating awareness of the issue [1, 5, 9, 11, 12].

  11. Sammy Azdoufal discovers critical security flaw in DJI Romo robot vacuums, accessing thousands of devices

    Sammy Azdoufal discovers a critical security vulnerability in DJI's Romo robot vacuums while attempting to control his unit with a PS5 controller and an AI-assisted custom app, gaining access to thousands of devices [1, 2, 3, 6, 7, 8, 9, 12].