Ecovacs robot vacuums can be hijacked remotely to spy on you2024-08-12 19:34 by DanielaTags: Ecovacs, Bluetooth, hackers
A pair of security researchers have discovered that Ecovacs vacuums and lawn mowers can be hijacked over a Bluetooth connection. These devices, which contain cameras and microphones, may be utilized for "spying" if compromised. Concerningly, Ecovacs has not acknowledged the problem. The security researchers in question - Dennis Giese and Braelynn - identified several vulnerabilities in Ecovacs products and cloud-based services. The Bluetooth takeover flaw is simply the most notable of the bunch. Hackers can hijack Ecovacs robotic vacuums and mowers by sending a malicious payload over Bluetooth from a smartphone. Once an Ecovac robot is compromised, hackers may access its cameras and microphones. They may also drive the robot like an RC car, download its room-mapping data, tinker with its filesystem, or use it to hack nearby Ecovacs devices. Importantly, an attacker must be within Bluetooth range (less than 450 feet) to perform this hack. Ecovacs vacuums regularly disable their Bluetooth connection throughout the day, so an attacker needs to be fairly patient, and some Ecovacs robots play a repetitive warning noise when their camera is turned on. However, attackers can set up Wi-Fi remote access after completing the Bluetooth hack. They only need to be in physical proximity for a few minutes. And because a hacker can dig through a compromised robot's filesystem, they may delete the files associated with the "camera-on" warning noise. Plus, Bluetooth hijacking is just one of many flaws discovered by Giese and Braelynn. The duo found that cloud-based user data and authentication tokens are not discarded when a user deletes their Ecovacs account. If Ecovacs' servers are compromised, former customers may have their private data exposed. And if you sell an Ecovacs vacuum to someone, you can use your old authentication token to spy through the vacuum. Read more -here-
Post your review/comments
rate:
avg:
|