A vulnerability in DJI’s Romo robot vacuum’s cloud system has uncovered a broader weakness in the security of networked home devices, highlighting the dangers of broad access controls and persistent exposure in connected home tech.
A security lapse in DJI’s Romo robot vacuum has exposed a wider weakness in the design of cloud-connected home devices, after a researcher was able to reach thousands of machines by using a valid token from his own unit.
Sammy Azdoufal, an AI strategist based in Barcelona, was experimenting with voice and controller input on his own vacuum when he found that DJI’s cloud messaging system would accept his device credentials for far more than one machine. Reports from The Verge, TechRadar and other outlets say the flaw allowed access to around 6,700 Romo devices in more than 20 countries, with live camera feeds, microphone audio, floor maps and sensor data among the information that could be viewed.
The technical fault was not in the encryption protecting traffic in transit, but in the way DJI’s server-side permissions were handled. Security coverage published by TechRadar and UBOS Tech said the company’s MQTT broker lacked proper topic-level access controls, meaning an authenticated client could subscribe broadly and read messages from other devices in plain text. That is a classic access-control failure: the network may be encrypted, yet the backend still hands out data too freely.
The episode has already drawn comparisons with other smart-home security failures. TechRadar and other reports noted past incidents involving Ecovacs, Dreame, Wyze, Anker Eufy, Narwal and iLife, where weaknesses in authentication, remote access or cloud handling exposed video, maps or device control. The pattern matters because these products are no longer simple appliances; they are networked agents with microphones, cameras and persistent access to private spaces.
DJI has since issued fixes, according to reports cited by TechRadar and UBOS Tech, but some problems appear to have remained after the first patches. Coverage from DroneXL and The Verge said two updates in February addressed the wildcard access issue, yet at least one vulnerability, including video access without a PIN, was still being discussed later in the month. That makes the Romo case more than a one-off bug. It is a reminder that partial remediation in connected devices can leave serious exposure in place.
For the broader industry, the lesson is straightforward. If a home robot depends on central cloud permissions that are too broad, one leaked credential can become a gateway to many devices. The Romo incident shows why access controls, local validation and limited data exposure are now core security requirements, not optional extras.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





