DJI Romo Robot Vacuum Security Vulnerabilities
DJI paid security researcher Sammy Azdoufal a $30,000 bug bounty on March 7, 2026, for discovering a critical flaw in its Romo robot vacuums that exposed live camera feeds, microphone audio, and home mapping data from approximately 7,000 devices. As of June 4, 2026, primary vulnerabilities have been patched, but secondary issues, including a PIN bypass for camera access, remain unaddressed, with DJI promising further fixes. The vulnerability also affected DJI Power portable battery stations due to authentication tokens not being scoped to individual devices, raising ongoing concerns about data security and potential data transmission to China. DJI is using findings from a recent independent cybersecurity audit of its drone systems, which found no critical vulnerabilities, in its appeal against the FCC's Covered List designation, despite the Romo flaw.
Timeline
Want updates on this thread?
Track this storyTimeline of developments
June 2026 — 1 developments
DJI Drone Security Audit Finds No Critical Flaws Amidst Romo Vacuum Vulnerability Scrutiny
An independent cybersecurity audit of DJI's drone systems, conducted between October 2025 and March 2026, found no critical, high, or medium-risk vulnerabilities. DJI is using these findings in its appeal against the FCC's Covered List designation, despite a recent security flaw in its Romo robot vacuum.
March 2026 — 2 developments
DJI Romo robot vacuum flaw exposed camera feeds, audio, and home mapping data
A significant security flaw in the DJI Romo robot vacuum allowed unauthorized access to live camera feeds, microphone audio, and home mapping data for thousands of devices. The vulnerability, which also affected DJI Power portable battery stations, stemmed from authentication tokens not being scoped to individual devices. DJI faces ongoing scrutiny regarding data security and privacy, with concerns about potential data transmission to China.
DJI pays $30,000 bug bounty to researcher for critical Romo robot vacuum flaw
DJI has paid a $30,000 bug bounty to security researcher Sammy Azdoufal for discovering a critical flaw in its Romo robot vacuums. The vulnerability exposed approximately 7,000 devices to potential remote access, including cameras. Azdoufal discovered the flaw accidentally while attempting to control his own Romo vacuum.
February 2026 — 11 developments
DJI promises further fixes for unaddressed secondary vulnerabilities, including PIN bypass
As of the current date, primary vulnerabilities are patched, but secondary issues, including a PIN bypass for camera access, remain unaddressed, with DJI promising further fixes [1, 2, 12].
DJI to address remaining security issues "within weeks"
DJI indicates that remaining security issues will be addressed "within weeks" [3, 12].
TipRanks and Android Headlines report on DJI privacy implications and reputation damage
Further reporting by outlets like TipRanks and Android Headlines emphasizes the privacy implications and the potential damage to DJI's reputation, especially given previous security scrutiny [3, 4].
Vulnerability allowed access to Romo vacuums and DJI Power battery stations
It is reported that the vulnerability allowed access not only to Romo vacuums but also to DJI Power portable battery stations sharing the same infrastructure [1, 12].
Tech Outlets Analyze DJI Romo Vulnerability, Detail MQTT Broker Access Controls
Multiple technology news outlets, including Android Authority and Malwarebytes, publish in-depth analyses of the DJI Romo vulnerability, explaining the technical cause (MQTT broker access controls) and the extent of data exposure [1, 2, 8, 12].
TechBriefly Reports DJI Patch Deployed, Azdoufal Claims Remaining Vulnerabilities
TechBriefly reports on DJI's patch deployment but notes Azdoufal's claim that secondary vulnerabilities remain unaddressed [5].
DJI Patches Security Issue, Claims No Malicious Exploitation
DJI states that the security issue has been patched, with remediation deployed in two updates, and claims no evidence of malicious exploitation [5, 9].
The Verge Reports DJI Romo Vulnerability Discovered by Sammy Azdoufal
The Verge publishes its initial report detailing the DJI Romo vulnerability, highlighting Sammy Azdoufal's discovery and the potential for remote access to approximately 7,000 units globally [7, 9, 11].
DJI deploys second patch, completes initial fix for Romo platform wildcard access issue
DJI deploys a second automatic patch, completing the initial fix for the main wildcard access issue affecting the Romo platform [1, 4, 5, 9, 11].
DJI deploys first automatic patch for Romo robot vacuum vulnerability
DJI deploys the first automatic patch to address the primary vulnerability in its Romo robot vacuums, indicating awareness of the issue [1, 5, 9, 11, 12].
Sammy Azdoufal discovers critical security flaw in DJI Romo robot vacuums, accessing thousands of devices
Sammy Azdoufal discovers a critical security vulnerability in DJI's Romo robot vacuums while attempting to control his unit with a PS5 controller and an AI-assisted custom app, gaining access to thousands of devices [1, 2, 3, 6, 7, 8, 9, 12].