SECURITY·중요도 8·2026. 07. 16.·The Hacker News
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
── KO ──────────────────
Shark 로봇 청소기의 취약점으로 공격자가 다른 기기를 원격 제어할 수 있는 문제가 발견됐다.
Shark RV2320EDUS 로봇 청소기에서 패치되지 않은 취약점이 발견됐다. 공격자는 이 취약점을 이용해 같은 AWS 지역 내 다른 Shark 청소기를 원격으로 제어할 수 있으며, 카메라를 감시하거나, 로봇을 이동시키고, 집의 지도를 읽고, Wi-Fi 비밀번호를 평문으로 획득할 수 있다. 연구자는 해당 방법을 발표하며 리서치를 공개했다.
── EN ──────────────────
Unpatched flaw in Shark vacuum allows attackers to control other vacuums in the same region.
An unpatched vulnerability in the Shark RV2320EDUS robot vacuum has been discovered, which allows attackers to control other Shark vacuums within the same AWS region. Exploiting this flaw, they can access the camera, maneuver the robot, view the house's map, and retrieve the Wi-Fi password in plaintext. A researcher named tokay0 has published the method online.