Researchers have uncovered 14 vulnerabilities in Mammotion’s cloud services, potentially affecting hundreds of thousands of users across more than 85 countries. The flaws could enable unauthorised access, data breaches, and remote control of connected robotic lawnmowers, prompting a company-led security response.
Security researchers have identified 14 vulnerabilities in Mammotion’s cloud services for its connected robotic lawnmowers, flaws that could expose user data and, in some cases, allow a mower to be controlled remotely. According to the reports provided by Journal du Geek and Cybercanal, the weaknesses affected several parts of the company’s online infrastructure and showed that a device could be linked to an unauthorised account, then operated through the Mammotion app as if it belonged to that user.
The most striking finding concerns scale. The researchers estimated that about 337,000 accounts may have been exposed through the weaknesses, although that figure does not mean 337,000 confirmed victims. The data at risk reportedly included email addresses, account identifiers, region information and various technical details. The exposure also extended across Mammotion’s regional infrastructure, with users in more than 85 countries, including France, Germany and Sweden, appearing in the affected environment.
Some of the vulnerabilities went further still by revealing Wi-Fi configuration data, including network names and other technical information, while in some scenarios authentication data was also implicated. Because the lawnmowers rely on cloud-based commands, attackers would not have needed to be physically near a machine to interact with it. In practical terms, that meant a mower could theoretically be taken over from anywhere once associated with the wrong account.
The researchers, identified in the reports as Sammy Azdoufal, Andreas Makris and Kevin Finisterre, disclosed the issues to Mammotion before publishing their findings. The company then spent several months working through fixes, meaning the 14 vulnerabilities should not be assumed to remain exploitable today. The case follows wider scrutiny of security in connected home devices, where recent research on robot mowers has also highlighted the value of PIN locks, alarms, GPS tracking and other anti-theft protections as baseline safeguards.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





