2K
A security vulnerability in Shark vacuums allows unauthorized access to other connected devices within the same Amazon Web Services region. The flaw is related to how AWS IoT certificates were implemented by SharkNinja. Despite efforts to address the issue, a patch has not been released as of the latest update.
Understanding the Shark Vacuum Vulnerability
The vulnerability stems from the unique AWS IoT certificates present in each Wi-Fi enabled Shark vacuum. By accessing the device’s U-Boot console without authentication, an attacker can retrieve the certificate files located at /mnt/res/vapp/certs/. This access does not require any login credentials.
While the certificate itself is not problematic, the associated AWS IoT policy lacks proper device scoping. This oversight allows the same credentials to interact with multiple vacuums in the region, subscribing to MQTT topics and manipulating AWS IoT Shadow states. This could potentially lead to unauthorized access and control over various functions of the affected devices.
The vulnerability has been confirmed across different Shark vacuum models, showcasing the widespread impact of the issue. Using a certificate obtained from one device, the researcher was able to execute commands on a separate vacuum, gaining access to sensitive information such as camera feeds, movement controls, home maps, and Wi-Fi passwords.
Implications for Millions of Devices
An analysis of MQTT traffic in a specific AWS region revealed a significant number of affected devices, highlighting the extent of the security lapse. The lack of device-specific scoping in the AWS IoT policy points to a systemic error in SharkNinja’s cloud setup, potentially affecting other connected products under the brand.
Addressing the issue requires revising the AWS IoT policies on SharkNinja’s cloud account rather than deploying firmware updates to individual devices. Despite being notified about the vulnerability earlier in the year, the company has yet to implement a solution, leaving owners with the only recourse of disconnecting their vacuums from Wi-Fi.
Ongoing Concerns and Future Mitigations
The discovery of this vulnerability underscores the broader risks associated with shared or inadequately scoped device certificates in IoT devices. Similar security oversights have been observed in various connected product categories, emphasizing the need for robust device-to-cloud trust mechanisms.
While the Shark vacuum vulnerability presents a significant security challenge, the solution lies in updating cloud policies rather than device firmware. The timely implementation of corrective measures by SharkNinja is crucial to mitigating the risk and safeguarding the privacy and security of users.



