Roborock discloses insecure random-number generator flaw in Tuya IoT cloud connection
S1 · 15 Sep 2021 · Roborock
Record
| Company | Roborock |
| Industry | Consumer robotics |
| Type(s) | cyber |
| Date | 15 Sep 2021 (day precision) |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | (near-miss / disclosed vulnerability) |
| Scale | 5 models |
| Confidence | high |
| Verified flag | Cited source on file; not independently re-verified |
Summary
Roborock disclosed that certain models (S6, S5 Max, S6 Pure, S6 MaxV, S4) connecting through Tuya's IoT cloud used a weak random number generator when negotiating the communication channel, potentially exposing device info, maps, and cleaning records; fixed via firmware update, no known exploitation reported.
Primary source
Publisher: Roborock (vendor disclosure) · Retrieved: 2026-09-16
Supporting source rows (1)
| Date | Supporting source row | Publisher | Link |
|---|---|---|---|
| 15 Sep 2021 | Roborock discloses insecure random-number generator flaw in Tuya IoT cloud connection | Roborock (vendor disclosure) | Roborock |
Consumer robotics context
cyber context
Roborock industry position
Related incidents
Other Roborock entries
- None on file.
Report a correction
Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs