Drooid Logo
Back to story perspectives

Full Breakdown

DJI Addresses Security Vulnerabilities After Researcher's Discovery

3/7/2026, 11:02:53 AM

Discovery of a Major Security Flaw

On Valentine's Day, security researcher Sammy Azdoufal inadvertently uncovered a significant security vulnerability while attempting to control his DJI Romo robot vacuum using a PlayStation gamepad. This exploration revealed a network of approximately 7,000 unsecured DJI Romo robots, which could potentially allow unauthorized access to the cameras within users' homes. The incident quickly garnered international attention, raising concerns about privacy and security for thousands of households.

DJI's Response and Compensation

In response to Azdoufal's findings, DJI has agreed to pay him $30,000 for his discovery, marking a notable shift in the company's approach to security researchers. Previously, DJI faced criticism for its treatment of researchers, particularly regarding its handling of Kevin Finisterre in 2017, who encountered similar issues while trying to report vulnerabilities. DJI confirmed the payment to Azdoufal but did not specify which discovery it pertains to. The company stated that it has already addressed one of the vulnerabilities, which allowed access to the Romo's video stream without a security PIN, and anticipates completing further system upgrades within a month.

Ongoing Security Measures

DJI has publicly committed to enhancing the security of its Romo robot vacuums. In a blog post, the company asserted that it has received certifications from ETSI, EU, and UL for security, although the effectiveness of these certifications has been called into question given the recent breach. DJI emphasized its dedication to collaborating with the security research community and plans to introduce new methods for researchers to engage with the company.

Criticism and Concerns

Despite DJI's assurances, skepticism remains regarding the effectiveness of its security measures. Critics have pointed out that the ability of a single individual to access a vast network of devices raises serious questions about the robustness of the company's security protocols. The incident has sparked discussions about the responsibilities of tech companies in safeguarding user privacy and the importance of transparent communication with the security research community.

Verbatim Quotes

  • “We can confirm that the PIN code security observation was addressed by late February,” — Daisy Kong, DJI Spokesperson
  • “Updates have been deployed to fully resolve the issue.” — DJI Blog Post
  • “committed to deepening our engagement with the security research community, and we will soon introduce new ways for researchers to partner and collaborate with us.” — DJI Blog Post

What's Next

As DJI continues to implement security updates and engage with the research community, the company faces the challenge of restoring its reputation among security experts. The incident serves as a reminder of the critical need for ongoing vigilance in cybersecurity, particularly as smart home devices become increasingly prevalent.