securityonline.info 6/17/2026, 2:50:28 AM · external

Hard-coded Yarbo app flaws let attackers hijack robot fleet

Hard-coded Yarbo app flaws let attackers hijack robot fleet
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Not in KEV
Patch Patch Status Unknown

SECURITY researchers have identified critical vulnerabilities in the Yarbo robot's mobile apps. The first vulnerability (CVE-2026-10557) involves hard-coded MQTT credentials common across all devices, allowing attackers to exploit and control the entire robot fleet by simply decompiling the app. The second issue (CVE-2026-7368) is a lack of authorization checks, granting valid users access to every robot after logging in.

Users are advised to update to version 3.17.4 of the app, and fixes will be implemented automatically via a future cloud update. Both vulnerabilities exemplify common security flaws in connected devices.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline