S1 · 09/15
2021 ·
Roborock
| Company | Roborock |
| Category | consumer robotics |
| Type | cyber |
| Date | 09/15 2021 |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | S1 (near-miss / disclosed vulnerability) |
| Scale | 5 models |
| Confidence | high |
| Verification | Cited source on file; not independently re-verified |
| Source | Roborock (vendor disclosure) |
Roborock disclosed that certain models (S6, S5 Max, S6 Pure, S6 MaxV, S4) connecting through Tuya's IoT cloud used a weak random number generator when negotiating the communication channel, potentially exposing device info, maps, and cleaning records; fixed via firmware update, no known exploitation reported.