Three independent cybersecurity researchers—Sammy Azdoufal, Andreas Makris, and Kevin Finisterre—identified 14 critical security flaws in the infrastructure supporting Mammotion's smart lawn mowers. These vulnerabilities could have exposed up to 337,000 user accounts, allowed access to connected networks, and even enabled remote control of the devices. The researchers focused on Mammotion's mobile app, which controls the lawn mowers, and discovered a method to access an admin account on the company's cloud infrastructure using just two unauthenticated requests. Their findings were detailed in a report highlighting the full range of vulnerabilities they uncovered.
The researchers demonstrated the risks by performing an account-hacking attack on a lawn mower they owned, claiming they achieved nearly complete control over the device. They could remotely operate the robot and view camera footage. While they did not fully explore all exposed cloud services, they outlined a significant attack surface, estimating that 337,000 user accounts could be accessed without authentication. These accounts were spread across four regional servers, with one in the European Union serving 85 countries, and a notable concentration in Germany, France, and Sweden. Approximately 49,000 of these accounts were linked to French users.
The access the researchers discovered enabled them to retrieve sensitive network information from each device, such as GPS coordinates, local IP addresses, MAC addresses, mobile connection IMEI numbers, home Wi-Fi SSIDs, and SIM card IMSI numbers—without verifying ownership. They also identified 46,785 RTK (Real-Time Kinematic) stations, which are used to improve the precision of GPS for robot mowers, and found that their RSA-2048 encryption keys could be retrieved without verification. These RTK stations are often sold by Mammotion and other manufacturers as accessories.
One of the most concerning vulnerabilities involved Mammotion's cloud access. The researchers found that the company's application referenced an endpoint connected to a server in China, which provided a One-Time Password (OTP) without requiring authentication or a token. This OTP, normally used for password recovery, was not time-limited and was permanently available for the admin account. This meant that with just two unauthenticated HTTP requests, the researchers could access the administrator account, bypassing standard security measures.
In response to the report, Mammotion acknowledged the researchers’ findings and stated it had implemented "protection measures." However, the company refused to establish a formal technical channel for responsible disclosure, despite working with external security institutions. While it fixed the most severe vulnerabilities, three issues remained unresolved, including a hard-coded secret in a public JavaScript file, a client registration process that could be exploited for phishing, and internal subdomains accessible via public DNS. Mammotion has not responded to further inquiries since being contacted on August 24.
Cybersecurity Researchers Identify Critical Vulnerabilities in Mammotion Lawn Mowers
AI-rewritten from original reportingHow it works
cybersecurityvulnerabilitiesmammotiondata-exposureremote-controlsecurity-breach
Original sources:
- 🇫🇷Next



