Hack one Shark vacuum & control millions of them: RCE using MQTT and hardcoded credentials ๐จ๐ปโ๐ป๐ช๏ธ๐งน๐๐ง
Security researcher tokay0 shared research earlier this month on Shark vacuums from SharkNinja, partially disclosing a critical, unpatched remote code execution vulnerability (RCE) affecting millions of Shark devices.
We do not have the full PoC yet, but we can get some technical details from the blog post:
โญ The author analyzed the device and was able to access the local file system.
โญ There, they were able to find AWS IoT client credentials.
โญ The MQTT server had broad authorization policies, which allowed an attacker to send commands to other devices.
๐ Bingo.
Classic. Good research. I recommend it as a practical example for anyone looking to understand why hardware security matters for more than just one device.
Stay safe, and do not use hardcoded credentials! :)
More details:
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE [Blog]: https://tokay0.com/posts/millions-of-shark-vacuums-vulnerable-to-rce.html


