RobotRisk Autonomous Systems Incident & Risk Register
RobotRiskRoborock › 15 Sep 2021

Roborock discloses insecure random-number generator flaw in Tuya IoT cloud connection

S1 · 15 Sep 2021 · Roborock

Record

CompanyRoborock
IndustryConsumer robotics
Type(s)cyber
Date15 Sep 2021 (day precision)
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
Severity (near-miss / disclosed vulnerability)
Scale5 models
Confidencehigh
Verified flagCited source on file; not independently re-verified

Summary

Roborock disclosed that certain models (S6, S5 Max, S6 Pure, S6 MaxV, S4) connecting through Tuya's IoT cloud used a weak random number generator when negotiating the communication channel, potentially exposing device info, maps, and cleaning records; fixed via firmware update, no known exploitation reported.

Primary source

Roborock (vendor disclosure)

Publisher: Roborock (vendor disclosure) · Retrieved: 2026-09-16

Supporting source rows (1)
DateSupporting source rowPublisherLink
15 Sep 2021 Roborock discloses insecure random-number generator flaw in Tuya IoT cloud connection Roborock (vendor disclosure) Roborock

Consumer robotics context

cyber context

Roborock industry position

Related incidents

Other Roborock entries

Report a correction

Open a prefilled GitHub issue

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs