Food Delivery Robots Vulnerable to Hacks That Redirect Orders
A vulnerability was identified in Pudu Robotics' management APIs, which potentially allowed unauthorized access to the company's food delivery and service robots. This issue could have enabled unauthorized redirection of robots such as BellaBots,…
A vulnerability was identified in Pudu Robotics' management APIs, which potentially allowed unauthorized access to the company's food delivery and service robots. This issue could have enabled unauthorized redirection of robots such as BellaBots, resulting in service disruptions in various sectors including restaurants, hospitals, and offices.
Pudu Robotics, a leading manufacturer of commercial service robotics, provides solutions to several industries, including:
Delivery robots: BellaBot, KettyBot, and PuduBot. Cleaning robots: CC1 and PUDU SH1. Disinfection robots with UV and chemical sprayers. Elevator-compatible robots with mechanical arms.
An investigation revealed that numerous API endpoints on Pudu's robot-management platform did not have adequate authentication checks. While valid tokens were required, the system did not verify user permissions or robot ownership. Consequently, potential attackers could:
An investigation revealed that numerous API endpoints on Pudu's robot-management platform did not have adequate authentication checks.
Access any robot’s call history and handle up to 20,000 store IDs in a single request. Initiate, cancel, or redirect tasks on any robot globally. Alter robot settings, including nicknames and configurations. Enumerate global store deployments and list robots by store ID.
In restaurants, an attacker could redirect meal deliveries, cancel requests, or disrupt service. In office settings, robots with elevator access could retrieve confidential documents. In healthcare, unauthorized actions could interfere with medicine delivery or disrupt critical disinfection tasks.
Attempts to report these vulnerabilities to Pudu Robotics began on August 12. Despite multiple communications, no immediate action was taken until after notifying major clients. Following this, Pudu's security team acknowledged the issue and confirmed patches were deployed.
This incident highlights significant gaps in security and responsiveness. The lack of dedicated security contacts and delayed handling of vulnerability reports suggest a need for improved security protocols. The event underscores the importance of robust security measures in technologies used in critical operations.
As the use of commercial service robots increases, manufacturers must ensure comprehensive security from design to deployment to maintain trust and operational integrity.
Based on reporting by GBHackers.
