Critical Yarbo Robot Vulnerability Exposes Global Fleet
ID: e10f947b-01cd-52a8-8e4b-571e63a71eb9
STIX ID: report--e10f947b-01cd-52a8-8e4b-571e63a71eb9
Feed Name: securityonline.info
Threat Score
**Yarbo robot fleet exposed:** Two vulnerabilities in Yarbo mobile apps/cloud (CVE-2026-10557 — hard-coded MQTT credentials, CVSS 9.8; and CVE-2026-7368 — missing per-device authorization, CVSS 8.1) allow an attacker who extracts the embedded credentials to subscribe to telemetry and publish commands to any device by serial number; users should update the app to 3.17.4+ and the vendor will enable server-side broker authorization with the May 2026 cloud update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
