Buying Guides
2026 Valetudo Exploit & OTA Lockout Tracker
Live matrix tracking silent PCB revisions, secure-boot floors, and firmware versions that block Valetudo local rooting on supported robot vacuums—OTA sunset dates and UART paths.
Valetudo supported robots in September 2026 still number only 49 SKUs on the maintainer’s Supported Robots page—but OTA laptop exploits are effectively dead on anything you can buy new at retail. Factory stock now routes through UART service-port chains (Dreame/MOVA/Xiaomi-Dreame), signed-bootloader FEL disassembly (Roborock S6–Q7 Max), or hard locks (wrong serial twins, SkyHigh NAND, unsupported name-twins). This tracker maps when each exploit interface closed, which firmware builds gate secure boot, and which silent PCB revisions block root even when the marketing name matches a supported model.
Quick answer: Which exploit paths work for valetudo supported robots in 2026?
OTA/laptop exploits survive only on legacy Roborock S5 (FW ≥ 2008) and pre-March-2020 Xiaomi V1 used stock. All factory-new 2025–2026 supported Dreame flagships root via 3.3 V UART + Hypfer breakout PCB past secure-boot firmware floors. Roborock S6–Q7 Max need full disassembly; Q7 Max 2024+ factory units may ship SkyHigh NAND that blocks FEL after teardown. Confirm exact SKU on valetudo.cloud—49 models only.
Source: Valetudo Supported Robots
Methodology: how this exploit tracker was built
On 6 September 2026, we re-read every model block on Supported Robots and classified each entry by root interface (OTA, UART, disassembly), documented lockout type (secure-boot floor, NAND vendor, PCB twin, post-flash config trap), and upstream date notes where maintainers recorded when a path changed1. Hardware context for UART pad layout was cross-checked against Dennis Giese’s corpus on robotinfo.dev where service-port photos matter, but lock vs root decisions follow maintainer install prose only2.
Where I’m less sure — reseller “new old stock” may ship firmware below documented secure-boot floors even on otherwise supported SKUs; you may need a temporary vendor Wi-Fi join to pull updates before UART install1. Anecdotally, buyers who assume “firmware downgrade unlocks OTA” waste more weekends than the $25 UART adapter costs.
Original research: OTA sunset and exploit-interface matrix
This citable dataset is the page’s original research: a chronological lockout map of how each exploit family died or narrowed on supported hardware. Rows reflect upstream-documented status as of 6 September 20261.
| Exploit era | Representative models | Interface | OTA status (Sep 2026) | Documented lockout | Factory-new buyer reality |
|---|---|---|---|---|---|
| 2016–2019 | Xiaomi V1, Roborock S5 | Laptop OTA | Open on matched used stock | V1 mfg after 2020-03 → disassembly only; S5 needs FW ≥ 2008 | Used-market only |
| 2019–2021 | Roborock S6, S6 Pure, S4 | FEL disassembly | Closed (signed boot) | Tray surgery; VibraRise mop on S7 complicates access | Not OTA—high mechanical risk |
| 2020–2023 | Dreame D9, L10 Pro, Z10 Pro | UART + breakout PCB | Never primary OTA | Secure-boot floors: L10 Pro ≥ 1138, Z10 Pro ≥ 1156 | Seals intact; update FW first |
| 2023–2024 | Dreame L10s Ultra, D10s Pro, L20 Ultra R2394 | UART + aarch64 secure boot | OTA dead | L20 R2253 twin hard lock; D10s vs D10s Pro name trap | Serial photo mandatory |
| 2024–2025 | Dreame L40/X40 Ultra, Master | UART + secure boot | OTA dead | Rebadged L10s Pro Gen3 “L40” twins unsupported | Exact model string on label |
| 2024+ | Roborock Q7 Max / Q7 Max+ | FEL disassembly | OTA dead | SkyHigh NAND ~Q2 2024+ factory per Sep 2024 upstream note | Post-teardown lottery |
| 2025–2026 | Dreame L40/X40 (Aug 2025+ mfg) | UART (unchanged) | OTA dead | Negative deviceId in did.txt — post-flash miio fix | Root succeeds; config trap |
”With a public root release, these get burned and usually quickly fixed by the vendors, making finding a working exploit chain for newer models after the release harder or sometimes even impossible.”
Stat snapshot: Of 49 supported models, only ~5 retain any OTA/laptop-first path—and none apply to 2025–2026 factory-new Dreame or Roborock flagships shoppers actually query in GSC data1.
The per-model install deep-links live in our supported robots matrix. The Dreame & Roborock 2025–2026 retail tracker covers name-twins; this page tracks exploit lifecycle and OTA closure.
Secure-boot firmware floors: versions that gate UART root
On Dreame aarch64 platforms, upstream documents minimum vendor firmware builds before the UART install script can persist Valetudo past U-Boot verification. These are floors (you must meet or exceed them), not ceilings that block rooting.
| Model cluster | Architecture | Secure boot | Minimum vendor FW (upstream) | Symptom if below floor |
|---|---|---|---|---|
| Dreame L10 Pro | aarch64 | yes | since FW 1138 | U-Boot rejects exploit payload |
| Dreame Z10 Pro | aarch64 | yes | since FW 1156 | UART connects; flash does not stick |
| Xiaomi Vacuum-Mop 2 Ultra | aarch64 | yes | since FW 1167 | Bootloader gate before root |
| Dreame D9 / F9 / MOVA Z500 | armv7 / lowmem | no | — | Try 500000 baud if UART garbled1 |
| Dreame L40 / X40 / X40 Master | aarch64 | yes | current vendor FW (join Wi-Fi briefly) | Same U-Boot verification chain |
Procedure: Join vendor Wi-Fi temporarily, confirm the About-screen build, update if below floor, then run the offline UART install from a UPS-backed Linux laptop1. I haven’t tested every regional firmware branch—EU vs CN builds sometimes lag the floor numbers upstream cites.
Silent PCB and storage lockouts (2024–2026)
Firmware floors are software gates. Silent PCB revisions and storage swaps are hardware gates that no downgrade fixes.
| Lock type | Affected retail names | Fingerprint | Discovered when | Workaround |
|---|---|---|---|---|
| Serial twin | Dreame L20 Ultra | R2394 ✓ / R2253 ✗ | Pre-purchase (label photo) | Buy different unit |
| SSID twin | Xiaomi 1C | AP dreame.vacuum.mc1808 only | Factory setup Wi-Fi scan | Do not root other dreame.vacuum.* SSIDs |
| Name rebadge | ”L40” marketing | Exact L40 Ultra string | Label check | L40s Pro Ultra unsupported |
| Gen2 PCB | Dreame L10s Ultra | No extendable mop + AI cam | Feature + label | Gen2 hard lock |
| NAND vendor | Roborock Q7 Max | SkyHigh silkscreen | After disassembly | None documented—safe but not rootable |
| Post-flash config | L40/X40/X40 Master, L10s Pro Ultra Heat | Negative did.txt on Aug 2025+ mfg | After successful UART root | Seven-step miio fix upstream1 |
Upstream’s 28 September 2024 Q7 Max update remains the canonical storage-lock note: after days of testing, FEL does not work on SkyHigh NAND. The robot is not bricked—you learn the outcome after warranty seals break1.
Exploit lifecycle: why public roots disappear
Vendors respond to public exploit releases on a predictable cycle—understanding it prevents buying hardware on outdated forum advice.
- Researcher or maintainer documents a chain (UART shell escape, OTA signing gap, FEL payload).
- Install scripts ship on valetudo.cloud — the supported-robots list grows or stabilizes.
- Retail volume absorbs the exploit — buyers root thousands of units over weeks.
- Vendor patches silently — new PCB spins, NAND vendors, secure-boot keys, or negative deviceIds on fresh lots.
- Forum posts lag reality — 2022 Q7 Max guides still rank while 2024+ stock fails.
Steel-man: “Just buy whatever is on sale and follow the latest YouTube root—UART always works eventually.”
Rebuttal: UART does work on matched Dreame SKUs—but Roborock Q7 Max SkyHigh, L20 Ultra R2253, and unsupported Qrevo/S8 lines have no documented chain at all1. The steel-man conflates “UART exists on some Dreame models” with “any LiDAR vacuum roots.” For privacy-first buyers, SKU verification on the exhaustive list beats chasing burned OTA exploits from threads written before the vendor’s silent PCB spin.
Named scenario: pre-purchase exploit check
Elena, Austin — privacy engineer, $600 budget, wants a September 2026 factory-new vacuum with local MQTT maps and no cloud account. She shortlists Roborock Q7 Max (LAN mode marketing), Dreame L40 Ultra, and a used Roborock S5 from Facebook Marketplace.
| Candidate | Exploit interface | Lockout risk | Elena’s outcome |
|---|---|---|---|
| Q7 Max (new) | FEL disassembly | SkyHigh NAND ~2024+ | Reject — post-teardown lottery1 |
| L40 Ultra (new) | UART + breakout PCB | Name twin / negative deviceId | Accept with label photo + post-root did.txt check |
| S5 (used, FW 2010) | Laptop OTA | Low if FW ≥ 2008 | Accept if she wants legacy nav, not 2026 LiDAR |
Verdict: Elena buys Dreame L40 Ultra with a seller serial photo, flashes vendor FW on guest Wi-Fi, UART-roots on Ubuntu, applies the negative deviceId fix if needed, and publishes MQTT to Home Assistant on VLAN 40. She skips Q7 Max because OTA is dead and NAND lockout is discovered only after disassembly.
Working checklist: verify exploit path before purchase
Checklist
- Confirm exact model on valetudo.cloud Supported Robots (6 September 2026 snapshot).
- Classify exploit interface: OTA (legacy only), UART breakout, or FEL disassembly.
- Dreame aarch64: plan vendor FW update past secure-boot floor before UART install.
- Capture fingerprints: serial prefix, Wi-Fi AP name, button count, About-screen FW build.
- Roborock Q7 Max: treat 2024+ factory stock as SkyHigh NAND lottery—avoid if seals must stay intact.
- Reject unsupported flagships (S8, Qrevo, L10s Ultra Gen2) regardless of forum exploits.
- Flash from UPS-backed Linux laptop—never interrupt power mid-write.
- Dreame Aug 2025+ builds: check did.txt for negative deviceId after root.
- Post-root: MQTT auth, Home Assistant integration, WAN deny on IoT VLAN.
Continue to our offline flash walkthrough once the exploit path is confirmed, and the silent PCB revision guide for pre-purchase fingerprinting.
Verdict
For privacy-conscious buyers in September 2026, treat OTA rooting as a historical footnote: only used Roborock S5 and pre-2020-03 Xiaomi V1 retain laptop-first paths. Factory-new supported robots route through Dreame UART + breakout PCB (with secure-boot firmware floors and occasional post-flash deviceId traps) or Roborock disassembly with a SkyHigh NAND lottery on Q7 Max. The exploit lifecycle means today’s working forum thread is tomorrow’s silent PCB revision—buy fingerprinted hardware on the 49-model list, not brand loyalty.
My position: If you need a 2025–2026 factory-new Valetudo path, buy Dreame L40 Ultra or D10s Pro with seller serial photos and budget a UART session—not an OTA afternoon. Choose used S5 OTA only if you accept legacy navigation. Avoid factory-new Q7 Max unless you explicitly accept post-disassembly NAND risk.
Primary sources
| ID | Source | URL |
|---|---|---|
| 1 | Supported Robots (canonical list + per-model rooting) | valetudo.cloud/pages/general/supported-robots/ |
| 2 | Dennis Giese — vacuum hardware overview | robotinfo.dev |
| 3 | Hypfer Dreame UART breakout PCB | github.com/Hypfer/valetudo-dreameadapter |
| 4 | Valetudo — Why Valetudo | valetudo.cloud/pages/general/why-valetudo/ |
| 5 | Valetudo official releases | github.com/Hypfer/Valetudo/releases |
| 6 | Buying supported robots | valetudo.cloud/pages/general/buying-supported-robots/ |
Frequently Asked Questions
Which valetudo supported robots still allow OTA rooting in 2026?
Only legacy paths remain: Roborock S5 (laptop OTA, vendor FW ≥ 2008) and Xiaomi V1 units manufactured before March 2020. Every other supported SKU on the 49-model list as of September 2026 requires UART breakout (Dreame/MOVA/Xiaomi-Dreame) or full disassembly with FEL tooling (Roborock S6 through Q7 Max). Factory-new 2025–2026 Dreame and Roborock flagships do not ship with a working OTA exploit chain.
What firmware versions block Valetudo rooting on Dreame vacuums?
Upstream documents secure-boot floors, not ceilings: Dreame L10 Pro since FW 1138, Z10 Pro since FW 1156, Xiaomi Vacuum-Mop 2 Ultra since FW 1167. aarch64 Dreame flagships from 2024–2026 generally need current vendor firmware before the UART install script persists Valetudo past U-Boot verification. Firmware below the floor rejects the exploit payload; firmware above the floor is required—not blocked.
When did Roborock close the OTA root path for Valetudo?
Roborock S6 (2019) onward moved to signed bootloaders that killed the laptop OTA exploit family. S5 OTA remains documented for used-market units with FW ≥ 2008. S6–S7 and Q7 Max require tray disassembly; Q7 Max factory stock from roughly Q2 2024 may ship SkyHigh NAND where FEL fails after days of testing per upstream’s September 2024 note.
What is the exploit burn cycle vendors use against public roots?
Upstream states that public root releases get burned and vendors usually patch UART and OTA paths quickly—sometimes making newer models impossible after release. This tracker records documented lockouts (NAND swaps, secure-boot floors, negative deviceIds) rather than predicting undisclosed patches. Buy supported SKUs with seller fingerprints before forum exploits spread.
Can I downgrade firmware to unlock an OTA exploit?
Generally no on modern Dreame aarch64 and Roborock signed-flash chains. Secure-boot floors require meeting a minimum vendor build before root—not rolling back to an older exploitable image. Roborock Q7 Max SkyHigh NAND is a hardware lock unrelated to firmware version. Treat downgrade threads as unverified unless upstream documents a specific path for your exact model.
How do I check if my robot is locked before opening the box?
Match the exact model string on valetudo.cloud Supported Robots, capture Wi-Fi AP name during setup (Xiaomi 1C), request a seller serial photo (L20 Ultra R2394 vs R2253), count top buttons (D9 vs D9 Max), and read the About-screen firmware build against documented floors. Q7 Max NAND vendor is the exception—you may only confirm SkyHigh storage after disassembly.