Work at iRobot? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
iRobot, the leading global consumer robot company, designs and builds robots that empower people to do more both inside and outside of the home. This program is testing iRobot's web applications, mobile applications, cloud APIs, and cloud-connected robots for vulnerabilities. NOTE! [Please Read Fully Before Beginning Or Engaging In Any Testing] Please DO NOT use automated vulnerability scanners when testing against the in-scope targets (Zap/Burp/Acunetix/Nikto/Nessus/etc) - all of these tools have already been run, and are run on a recurring basis internally. Running any tools of this nature is largely an inefficient use of your time and resources. However, you ARE encouraged to run any custom scripts or fuzzers that you have developed (e.g. niche file or directly wordlists, etc); however, please keep your requests using these tools to UNDER 50 requests per SECOND. In short, we strongly encourage researchers to perform manual testing by hand - this is where you're much more likely to achieve success, and a much better use of your time and resources, as opposed to running common tools that have already been used extensively against the in-scope targets, etc. Please be aware that Submissions found using pirated software will not be rewarded. Good luck, and happy hunting! Additionally, please be aware that this program does not accept out of scope submissions. Testing targets that are out of scope is strictly prohibited. Rules: This bounty does not allow disclosure. You may not release information about vulnerabilities found in this program to the public. If you have questions or need to contact iRobot or Bugcrowd, please contact support . You must ensure that customer data or devices are not impacted in any way as a result of your testing. Ensure that you are not being destructive while testing and that you are only testing targets that are in-scope. Submissions must be submitted in plain text formats. Supporting videos and images are fine as long as they are in standard, cross-platform formats. Submissions in other formats (e.g. DOCX, PDF, etc.,) will be asked to for resubmission in a plain text format. We are not interested in vulnerabilities that only affect robots under your possession and control unless it can be demonstrated that the same vulnerability would impact another customer's robot, mobile device, account, etc., What you can expect from us: We are committed to working with you as transparently and efficiently as possible. We will acknowledge receipt of your vulnerability report with 10 working days We strive to support you and work with you to solve the reported issue within 180 working days. Support will be provided on a best-effort basis, including for discontinued products. Ratings/Rewards For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
Scope
28 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| https://apps.apple.com/us/app/roomba-home/id6504274697 | ios | ✓ bounty | not set |
| https://aspen-ecommerce-prod.iot.irobotapi.com/dev/v1/ecommerce/entitlements/{entitlement_id} | api | ✓ bounty | not set |
| https://aspen-ecommerce-prod.iot.irobotapi.com/dev/v1/ecommerce/robots/{robot_id}/entitlements | api | ✓ bounty | not set |
| https://aspen-ecommerce-prod.iot.irobotapi.com/dev/v1/ecommerce/users/{user_id}/entitlements | api | ✓ bounty | not set |
| https://play.google.com/store/apps/details?id=com.irobot.home.prime | android | ✓ bounty | not set |
Show all 28 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| https://www.irobot.at/ | website | ✓ bounty | not set |
| https://www.irobot.be/ | website | ✓ bounty | not set |
| https://www.irobot.ca/en_CA | website | ✓ bounty | not set |
| https://www.irobot.ca/fr_CA/home | website | ✓ bounty | not set |
| https://www.irobot.co.uk/ | website | ✓ bounty | not set |
| https://www.irobot.com | website | ✓ bounty | not set |
| https://www.irobot.de/ | website | ✓ bounty | not set |
| https://www.irobot.es/ | website | ✓ bounty | not set |
| https://www.irobot.fr/ | website | ✓ bounty | not set |
| https://www.irobot.ie/ | website | ✓ bounty | not set |
| https://www.irobot.nl/ | website | ✓ bounty | not set |
| https://www.irobot.pt/ | website | ✓ bounty | not set |
| https://zuora-ecommerce-prod.iot.irobotapi.com/dev/v1/ecommerce/notifications/raas | api | ✓ bounty | not set |
| iRobot API Endpoint | api | ✓ bounty | not set |
| iRobot Roomba™ 105 | hardware | ✓ bounty | not set |
| iRobot Roomba™ 205 | hardware | ✓ bounty | not set |
| iRobot Roomba™ 405 | hardware | ✓ bounty | not set |
| iRobot Roomba™ 505 | hardware | ✓ bounty | not set |
| iRobot Roomba™ 705 | hardware | ✓ bounty | not set |
| https://answers.irobot.com | website | submit only | not set |
| https://investor.irobot.com | website | submit only | not set |
| https://media.irobot.com | website | submit only | not set |
| https://www.homesupport.irobot.com | website | submit only | not set |