logo

Critical Yarbo Robot Vulnerability Exposes Global Fleet

ID: e10f947b-01cd-52a8-8e4b-571e63a71eb9

STIX ID: report--e10f947b-01cd-52a8-8e4b-571e63a71eb9

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

**Yarbo robot fleet exposed:** Two vulnerabilities in Yarbo mobile apps/cloud (CVE-2026-10557 — hard-coded MQTT credentials, CVSS 9.8; and CVE-2026-7368 — missing per-device authorization, CVSS 8.1) allow an attacker who extracts the embedded credentials to subscribe to telemetry and publish commands to any device by serial number; users should update the app to 3.17.4+ and the vendor will enable server-side broker authorization with the May 2026 cloud update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.