HomeSecurityEcovacs robot vacuums are spying on their owners

Ecovacs robot vacuums are spying on their owners

Critical flaws in Ecovacs robot vacuums allow hackers to exploit these devices to spy on and harass owners.

See also: ORo: A robot “nanny” for your dog

Robot vacuum cleaners

The findings, presented at the DEF CON 32 by researchers Dennis Giese and Braelynn Luedtke, highlight serious security flaws in Ecovacs' popular Deebot models and other IoT, raising alarm about privacy risks in smart homes.

The vulnerabilities mainly concern Bluetooth and PIN authentication systems. Hackers can remotely connect to the Ecovacs robot vacuum cleaner via Bluetooth from distances of up to 130 meters.

Once connected, they can bypass weak PIN protections to gain complete control over the devices. This includes activating built-in cameras and microphones without the owner’s knowledge, effectively turning robot vacuums into spying tools.

See also: Robot vacuum cleaners hacked and chased pets

Additionally, researchers demonstrated that attackers could disable the camera's warning sounds by tampering with local audio files stored on the devices.

Ecovacs robot vacuums are spying on their owners

This allows hackers to spy on users without triggering alerts. Compromised devices can stream live video and audio streams through cloud services like AWS Kinesis, allowing hackers to monitor users from anywhere in the world.

The vulnerabilities affect multiple Ecovacs models, including but not limited to:

  • Deebot 900 Series
  • Deebot X1/X2
  • Deebot N8/T8 and N9/T9
  • Goat G1 lawnmower robots
  • Spybot Airbot Z1 and other Airbot models

Hacked Ecovacs robot vacuums often feature advanced hardware, including cameras, microphones, LiDAR sensors, and artificial intelligence navigation systems.

See also: The Enabot ROLA PetPal robot takes care of your pets

Serious security flaws can pose significant risks to systems, data, and user privacy. These vulnerabilities often arise from outdated software, weak encryption protocols , or inadequate security measures, leaving systems exposed to potential attacks. Exploitation of such flaws by malicious actors could lead to data breaches, identity theft, or unauthorized access to sensitive information. It is vital to identify, assess, and promptly address these flaws through regular updates, patch management, and adherence to strong security practices.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS