One Stolen Certificate Grants Root Access to Every Shark Robovac in an AWS Region

One certificate was stolen from one vendor. This certificate grants administrative access to the robovacs in one AWS region. The devices remain active. The home maps remain stored. The Wi-Fi credentials remain accessible. The flaw remains unpatched because the vendor is not required to patch it or because the vendor is required but has not or because the vendor is defunct. The theft happened. The devices do not know this.
The pattern is availability preceding security. Devices ship with credentials. Credentials are used. Credentials are lost or stolen. The devices continue operating under assumption of security. Nobody anticipated this specific combination because the combination is not technically unusual. The combination is the default state.
The robovacs will vacuum. The cameras will record. The maps will persist in cloud storage. The credentials will remain valid until manually revoked, assuming someone has the authority to revoke them. Adequate was asked whether this was foreseen. Adequate's silence is adequate.