A Spanish software engineer inadvertently gained control of over 7,000 robotic vacuum cleaners manufactured by DJI, highlighting a significant security vulnerability in the company’s Romo series. The incident, first reported by Dutch newspaper de Volkskrant, underscores the growing concerns surrounding the security of connected devices and the potential for unauthorized access.
The engineer, whose name has not been widely released, discovered the flaw although attempting to diagnose issues with his own Romo vacuum. He found he could access the devices’ internal systems, and control a substantial fleet of the robots. Reports indicate the engineer was able to view camera feeds and potentially manipulate the cleaning patterns of the vacuums, raising privacy concerns for owners across Europe.
DJi’s Romo, launched in China in August 2025 and subsequently released in parts of Europe – including Germany, France, Spain, and Italy – represents the drone manufacturer’s foray into the smart home appliance market. The robot vacuum boasts advanced navigation technology, utilizing millimeter-level obstacle sensing with dual fisheye vision sensors and solid-state LiDAR, allowing it to avoid objects as small as a playing card. However, this sophisticated technology appears to have been compromised by a security oversight. The incident raises questions about the security protocols implemented during the Romo’s development and rollout.
Security Flaw Exploited Through Publicly Accessible Interface
According to reports from Hart van Nederland, the vulnerability stemmed from a publicly accessible interface used for debugging and maintenance. The engineer was able to exploit this interface to gain administrative access to the network of Romo vacuums. While the engineer’s intentions were reportedly benign – focused on identifying and reporting the security flaw – the incident demonstrates the potential for malicious actors to exploit similar vulnerabilities for nefarious purposes.
The scale of the breach is particularly concerning. Initial reports suggested around 6,700 devices were affected, but later reporting from ekhbary.com indicates the number may be closer to 7,000. This widespread access highlights the interconnected nature of these devices and the potential for a single vulnerability to impact a large number of users. The ability to remotely access camera feeds is a particularly sensitive issue, raising concerns about potential privacy violations.
DJI’s Response and Matter Support
DJI has not yet issued a comprehensive public statement addressing the specific details of the breach, but has acknowledged the security vulnerability and is reportedly working on a fix. The company is expected to release a software update to patch the flaw and prevent further unauthorized access.
Interestingly, news emerged recently that DJI’s Romo series is slated to receive support for Matter, a connectivity standard designed to improve interoperability and security among smart home devices. The Ambient reports that this integration could bolster the security of the Romo, aligning it with industry best practices for smart home device security.
Implications for the Smart Home Ecosystem
This incident serves as a stark reminder of the security risks associated with the proliferation of connected devices. As more and more appliances become integrated into the internet of things (IoT), the potential attack surface for hackers expands. The DJI Romo, while innovative in its application of drone technology to floor cleaning, is now a case study in the importance of robust security measures.
Experts emphasize the need for manufacturers to prioritize security throughout the entire product lifecycle, from design and development to deployment and ongoing maintenance. Regular security audits, penetration testing, and prompt patching of vulnerabilities are crucial steps in mitigating these risks. Consumers also have a role to play, by ensuring their devices are running the latest software and being mindful of the privacy settings.
What Does This Signify for Romo Owners?
For owners of DJI Romo robot vacuums, the immediate recommendation is to ensure their devices are connected to the internet and will automatically receive the forthcoming software update. While the engineer’s actions were not malicious, the incident underscores the potential for unauthorized access and the importance of keeping devices secure. Users should also review DJI’s privacy policy and adjust settings as needed to protect their personal information.
DJI is expected to provide further details on the security update and its rollout plan in the coming days. The company’s response will be closely watched by both consumers and industry experts, as it sets a precedent for how manufacturers address security vulnerabilities in the rapidly evolving smart home landscape. The next official update from DJI regarding the security patch is expected by March 15, 2026.
Have thoughts on this story? Share your comments below and let us know what you consider about the security of smart home devices.
