{"id":73585,"date":"2025-08-16T21:43:12","date_gmt":"2025-08-16T21:43:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/73585\/"},"modified":"2025-08-16T21:43:12","modified_gmt":"2025-08-16T21:43:12","slug":"robot-vacuum-maker-dreames-smartphone-app-vulnerable-to-hacking","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/73585\/","title":{"rendered":"Robot vacuum maker Dreame&#8217;s smartphone app vulnerable to hacking"},"content":{"rendered":"<p class=\"paragraph_paragraph__iYReA\">A major Chinese robot vacuum maker&#8217;s smartphone app has a critical security flaw, leaving it susceptible to leaking user data and credentials if targeted by hackers.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">When the Dreame smartphone app is used on a public wi-fi network, like in a hotel or airport, any information sent over the internet can be read by the network administrator.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">This could include login details, personal information and data about the house where the user&#8217;s devices are located.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Dreame&#8217;s range of robot vacuum cleaners come equipped with cameras, microphones and connections to the internet, and are sold at more than a dozen Australian retailers, many of them well-known.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The vulnerability is the second one to hit a major home robotics company in as many years, increasing the scrutiny on Australia&#8217;s plans to launch a cybersecurity rating scheme for smart devices.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Security researcher Dennis Giese \u2014 <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2024-10-04\/robot-vacuum-hacked-photos-camera-audio\/104414020\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/104414020\" rel=\"nofollow noopener\" target=\"_blank\">who discovered a separate vulnerability in Ecovacs robot vacuums last year<\/a> \u2013 attempted to establish a contact at Dreame as early as 2021.<\/p>\n<p><img decoding=\"async\" alt=\"A man with long dark hair and a beard looks into a technical instrument in a lab.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/08\/328564a7f827da1a424deb1cb169762a\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Dennis Giese is an independent security and privacy researcher. (Supplied: Matthew Modoono\/Northeastern University)<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;I tried to get a security contact for the last four years,&#8221; says Giese.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;But they effectively ghosted me.&#8221;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">After failing to establish a reliable contact with Dreame, the researcher reported the vulnerability to US cybersecurity agency CISA.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">CISA reproduced the exploit, and assigned it a &#8220;<a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-219-06\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\">low attack complexity<\/a>&#8221; level in an alert it published last week. This means that the hack is not difficult to pull off for a sophisticated attacker.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The security flaw \u2014 a misconfigured check for security certificates in the app \u2014 allows network administrators to pretend to be Dreame&#8217;s own servers, and intercept user data.<\/p>\n<p>Do you know more? Or have a Dreame robot in your home?<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Contact Julian Fell at <a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2025-08-17\/dreame-smartphone-app-vulnerable-to-hacking\/mailto:tips@jtfell.com\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\">tips@jtfell.com<\/a><\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Captured communications may include user credentials and sensitive session tokens,&#8221; reads the CISA advisory note.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Dreame Technology did not respond to CISA&#8217;s request for coordination.&#8221;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The ABC has also verified the exploit by connecting a smartphone to a wi-fi network that Giese had set up.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The access point worked as expected. The phone was able to access the internet as usual when connected.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">However, when we logged into the Dreame app, the researcher was able to intercept our password.<\/p>\n<p><img decoding=\"async\" alt=\"A laptop on a desk, showing a computer terminal. The text shows a &quot;CRITICAL&quot; message associated with data sent to Dreame.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/08\/43470cf6111f989df5169772b19ab34b\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">The ABC verifying the exploit on a network configured by Dennis Giese. (ABC News: Julian Fell)<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Dreame said it had forwarded the ABC&#8217;s questions on to &#8220;the relevant teams for review&#8221;, but did not respond in time for publication.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;A formal statement addressing your questions will be provided to you once our assessment is complete,&#8221; the company said in an email.<\/p>\n<p>Certified secure by multinational testing company<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Dreame has its products certified as secure by a third-party.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Multinational testing company T\u00dcV S\u00dcD wrote in <a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.tuvsud.cn\/zh-cn\/resource\/gcn-en-pressrelease\/2022\/jun\/dreame-technologys-robot-vacuum-obtains-tuvsuds-etsi-en-303-645-aoc\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\">a 2022 press release<\/a> that it had &#8220;performed professional security tests and document reviews&#8221; on one of Dreame&#8217;s robot vacuum cleaners.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">It has continued to do so for newer models, one of which was completed as recently as August 2025.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">It is unclear whether the app itself was tested as part of this certification process.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">T\u00dcV S\u00dcD did not respond to the ABC&#8217;s questions.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Ecovacs&#8217; robots, which suffered from a separate security vulnerability, were certified to the same standard (called ETSI EN 303 645) by another testing company.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2024-10-04\/robot-vacuum-hacked-photos-camera-audio\/104414020\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">We hacked a popular robot vacuum \u2014 and could watch live through its camera<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Without even entering the building, we were able to silently peer through the camera on a Deebot device made by Chinese giant Ecovacs.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">This certification is mandatory for smart home products to be sold in Europe.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">It is intended to catch basic security flaws, yet several have been missed and later caught by external researchers after the products were released to the public.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Lim Yong Zhi, a former cybersecurity tester at T\u00dcV S\u00dcD, told the ABC in 2024 that these certification standards may provide a &#8220;false sense of security&#8221; to consumers.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">He said the testing process is largely &#8220;left open for interpretation&#8221; by those doing the testing.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">While the standard specifies that common security features must be present, said Lim, there is no explicit requirement that they are implemented correctly.<\/p>\n<p>Australia to implement smart labelling scheme<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The repeated failures of international cybersecurity certifications come as Australia prepares to implement its own scheme, planned to launch in 2027.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">In July, the government <a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.homeaffairs.gov.au\/news-media\/archive\/article?itemId=1331\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\">announced a voluntary labelling scheme<\/a> where companies can have their devices rated in terms of their cybersecurity protections.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The intention is to allow Australians to make more informed decisions about the security of the devices they are buying.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Australians need to be able to trust that the devices they bring into their homes won&#8217;t compromise their safety,&#8221; said Tony Burke, Australia&#8217;s minister for cyber security.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Whether it&#8217;s a smart speaker or robot vacuum cleaner, consumers will know how safe a product is before they buy it.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"A close up image of Tony Burke in a suit and tie. \" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/08\/1963c110632418d85b2f1e7b34ff90e4\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Cyber Security Minister Tony Burke says Australians need to be able to trust the devices they bring into their homes. (ABC News: Matt Roberts)<\/p>\n<p class=\"paragraph_paragraph__iYReA\">In recent weeks, the Department of Home Affairs has been consulting with Australian cybersecurity testing labs on the design of the scheme.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">One of the industry leaders who has been providing input is Viden Labs CEO Anthony Barnes.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">He says that the current rules and even proposed extensions to align with the ETSI EN 303 645 standard won&#8217;t guarantee that devices being sold in Australia are secure.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Companies in today&#8217;s economy win by being first to market, not necessarily by building the most secure product.&#8221;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;The current security standards only cover three of the 13 of the baseline security controls under the standard, which is not effective in identifying security vulnerabilities.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"Anthony Barnes sits at a desk in a nondescript office\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/08\/78ead96ada2f8d37dde2e5bae7ffdacc\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Viden Labs CEO Anthony Barnes has been providing input into the design of Australia&#8217;s smart device labelling scheme. (ABC News: Teresa Tan)<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Barnes is recommending that extra requirements are placed on how devices are tested, including &#8220;robust vulnerability testing and disclosure&#8221;.<\/p>\n<p>&#8216;No such thing as secure&#8217;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Home Affairs is partnering with industry group IOT Alliance Australia (IOTA) in designing the scheme.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Frank Zeichner, CEO of IOTA, says it is &#8220;pretty clear&#8221; what needs to be tested by labs under the ETSI EN 303 645 standard.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;There is enough [international] momentum with the ETSI standard that it&#8217;s heading in the right direction,&#8221; he says.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;We can&#8217;t do anything unique because no one will listen to it. The manufacturers will just ignore it.&#8221;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">A spokesperson for the Department of Home Affairs said &#8220;the co-design process will consider standards and labelling regimes in other jurisdictions.&#8221;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Zeichner added that the scheme may only cover the devices themselves, not the apps that they connect to \u2013 which means the Dreame vulnerability would not have been caught.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;There&#8217;s no such thing as secure,&#8221; he said. &#8220;There is only more secure.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"A major Chinese robot vacuum maker&#8217;s smartphone app has a critical security flaw, leaving it susceptible to leaking&hellip;\n","protected":false},"author":2,"featured_media":73586,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,57220,12460,46654,57221,105,33088],"class_list":["post-73585","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-dreame","tag-hack","tag-robot-vacuum","tag-smart-labelling-scheme","tag-technology","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/73585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=73585"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/73585\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/73586"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=73585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=73585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=73585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}