Three cybersecurity researchers have uncovered critical vulnerabilities in Mammotion’s connected robot lawnmowers, revealing a cloud-based control failure that could have allowed attackers to operate devices remotely and access user data, although the issues have now been fixed.
Three cybersecurity researchers have identified a set of flaws in Mammotion’s connected robot lawnmowers that, in the worst case, could have allowed one account to take over another user’s machine and operate it remotely. According to Frandroid, the researchers , Sammy Azdoufal, Andreas Makris and Kevin Finisterre , documented 14 vulnerabilities spanning the app, backend systems, account handling and device management. The company was notified before publication, and the issues have since been fixed.
The most serious weakness was not a local hack on the mower itself, but a cloud-based control failure. The researchers were able to attach a mower registered to another user to their own account and then issue commands as if they owned it. Because the instructions were routed through Mammotion’s cloud services, physical distance was irrelevant: a mower sitting in one garden could be controlled from elsewhere if the attacker could obtain the right access path.
FrenchBreaches reported that the team examined regional servers and identifier ranges and concluded that data linked to roughly 337,000 accounts across more than 85 countries could have been exposed. The information at issue reportedly included email addresses, account identifiers, customer numbers and geographic region. France, together with Germany and Sweden, was cited among the countries with the largest user bases. The researchers stressed, however, that they did not extract this information; the figure represents what could have been reachable through exploitation rather than a confirmed breach affecting all of those users.
The same reporting said some requests could also reveal saved Wi-Fi configuration data, including a home network name and, in some scenarios, associated authentication details. That would have given an intruder a direct route from cloud account abuse to the home network environment. The case also fits a broader pattern in consumer robotics security. TechSpot and the ACS article both described separate flaws in Yarbo lawn robots that exposed devices to remote control, while TechCrunch reported similar security concerns involving Ecovacs home robots. Together, the cases suggest that connected robots are still struggling with basic trust and access-control design, even as manufacturers increasingly market them as premium autonomous devices.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





