logo

Yarbo responds to robot flaws that could mow down their owners

ID: fd032ce2-7df9-542a-b601-ec01889ef196

STIX ID: report--fd032ce2-7df9-542a-b601-ec01889ef196

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

A security researcher demonstrated that Yarbo robotic lawn mowers worldwide were vulnerable to remote takeover due to legacy design flaws—shared hardcoded root credentials, persistent remote diagnostic tunnels, and weak MQTT messaging—allowing extraction of GPS, Wi‑Fi credentials, camera access, and bypass of emergency stops. Yarbo acknowledged the findings, temporarily disabled tunnels, reset credentials, locked down endpoints, and committed to per‑device credentials, OTA rotation, audited allowlist diagnostics, and a security contact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.