A security vulnerability in DJI’s Romo robot vacuum has left over 7,000 devices across 24 countries exposed to potential remote access, highlighting increasing concerns over data privacy and regulatory scrutiny of connected home robots.
DJI’s Romo robot vacuum has become an example of how a domestic convenience device can turn into a privacy risk when software controls fail. According to reports first published by The Verge and later relayed by technology outlets including Tom’s Hardware and TechRadar, U.S. software engineer Sammy Azdoufal was trying to make his own vacuum respond to a PlayStation controller when he uncovered a flaw that exposed thousands of other Romo units around the world. The issue did not break encryption, but it did appear to leave server-side access controls too weak to stop outsiders from reaching data belonging to other users.
The scope of the exposure was broad. Reporting on the incident said the vulnerability allowed access to live camera feeds, microphone audio, 2D floor plans and, in some cases, IP addresses that could indicate a device’s general location. One account said Azdoufal’s custom app received responses from roughly 6,700 vacuums in at least 24 countries, while another put the figure at more than 7,000 devices. In a security context, that means a flaw affecting a single household product could open a window into homes on multiple continents.
DJI has since said it addressed the problem and paid Azdoufal a $30,000 bug bounty, according to Tom’s Hardware. TechRadar reported that the company said one fix was already under way before the incident became public, although it also noted that another serious issue remained to be resolved. That mix of remediation and lingering concern reflects a common pattern in connected devices: manufacturers can patch one weakness, but trust is harder to restore once personal data has been exposed.
The episode comes as regulators are paying more attention to networked home robots. On July 28, the US Federal Communications Commission updated its Covered List to include foreign-made “advanced robotic devices” for the first time, a move that extends national-security scrutiny beyond phones and telecoms. The FCC says the category includes mobile robots that can navigate independently, operate at a distance from a human operator and use sensors, network connections and software for autonomous movement, perception or remote control.
That definition could affect products from major Chinese robotics brands such as Ecovacs, Roborock and Dreame, which may face a harder path to FCC authorisation for future models. The broader concern is not just market access but data handling: robot vacuums routinely map rooms, record audio and video, and upload information to the cloud. As the Romo case shows, the central question for buyers is no longer only how well a device cleans, but what it sees, what it stores and who can reach that information.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





