
Millions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to take over devices, access onboard cameras, and retrieve sensitive data stored on the robots.
Independent security researcher ‘tokay0' published a technical analysis after a months-long coordinated disclosure process with SharkNinja failed to result in a patch. According to the researcher, SharkNinja acknowledged receiving the report in March 2026 but had not remediated the issue by the time the vulnerability was publicly disclosed on July 13. The researcher also sought a CVE through MITRE after the standard 90-day disclosure period expired.
SharkNinja is a consumer appliance manufacturer best known for its Shark vacuum cleaners and Ninja kitchen products. Its connected robot vacuums rely on AWS IoT cloud services to enable remote control, mapping, scheduling, and mobile app integration.
The vulnerability stems from overly permissive AWS IoT policies assigned to device certificates. After extracting credentials from a purchased Shark vacuum during hardware analysis, the researcher discovered they could subscribe to MQTT topics belonging to other customers' devices instead of being restricted to their own vacuum.
Further analysis revealed that the devices accept a cloud command called Exec_Command, which is processed without adequate restrictions. By sending a specially crafted MQTT message to another vacuum, the researcher demonstrated arbitrary command execution on a second Shark model using credentials obtained from the first device.
The proof-of-concept was performed only on devices owned by the researcher. However, the report concludes that an attacker could abuse the same weakness to remotely execute commands on vulnerable Shark vacuums over the internet if they know or can guess a device's serial number.
tokay0
Beyond simply starting or stopping a vacuum, the researcher says successful exploitation could expose far more sensitive capabilities. Tested devices stored Wi-Fi credentials in plaintext, retained maps of users' homes, and, on camera-equipped models, allowed access to a live video feed. The researcher also demonstrated remotely controlling the vacuum's movement after gaining code execution.
To estimate the scope of the issue, the researcher monitored traffic on the AWS IoT infrastructure for 24 hours. During that period, more than 10.5 million MQTT messages were processed from roughly 1.5 million unique devices. Based on observed responses, at least 673,816 devices in a single AWS region appeared vulnerable to remote code execution, though the researcher believes the actual number of affected devices is likely higher.
The analysis also found that not all Shark devices use the same cloud access policies. An older firmware version on another Shark vacuum enforced stricter permissions, suggesting the insecure configuration may have been introduced during a later provisioning process rather than being present across all product generations.
At the time of publication, the vulnerability remains unpatched, and no CVE has been assigned. The researcher says they withheld exploit code to reduce the risk of abuse while awaiting remediation.
Until a fix is available, Shark robot vacuum owners should ensure their devices are running the latest firmware, monitor vendor security advisories for updates, and consider disconnecting internet-connected vacuums from the network when remote features are not needed, particularly if the devices include onboard cameras.






stop connecting junk to the internets AND stop using sh1tty routers
OPNsense is now for everyone