
DJI ROMO Security Breach: Researcher Remotely Accessed 7,000 Home Cameras — And One Hole Remains
Hook: A researcher in Barcelona remotely accessed ~7,000 DJI ROMO vacuums — live camera feeds, mics and floorplans — just by using his own device token. DJI’s MQTT broker lacked topic-level ACLs, letting authenticated clients read everything. Wildcard access was patched Feb 8 & 10, but one critical bug remains unpatched as of Feb 17; DJI says it’ll fix it “within weeks.” This puts fresh heat on DJI amid ongoing regulatory scrutiny.
Related Articles

2 hours ago 0
DJI Mini 5 Pro Now Available On Amazon Starting At $759 With Prime Shipping

2 hours ago 0
Inside DJI’s $3.2 Billion Sky: Frank Wang, Drones and Asia’s New Youngest Tech Billionaire

2 hours ago 0
RayNeo Air 4 Pro AR Glasses Work With DJI Mini 5 Pro and Avata 2, Offering a $249 Alternative to DJI’s $499 Goggles 3

9 hours ago 0
Beginners can capture 360° video footage in 4K with this DJI Mini 5 Pro — and it’s on sale right now