Skip to content
Cve 2026 7413

Cve 2026 7413

takeonme.org • May 7, 2026

AHA! has discovered an issue affecting Yarbo robot firmware v2.3.9. This disclosure follows AHA!’s standard disclosure policy . Any questions this disclosure should be directed to [email protected] .

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.

This vulnerability is estimated to have a CVSSv31 rating of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (7.2, High) and the relevant SSVC vectors are Exploitation: PoC and Technical Impact: Total . This issue is an instance of CWE-912 .

An undocumented SSH service is installed and listening on all affected robots, reachable through a NAT-pushing proxy system. This service grants an interactive shell at escalated, root privileges. The component is present in firmware images is routinely restored during normal boot, making access persistent.

An attacker who can reach the device either directly or through the supplied NAT-punching proxy and provide a valid username and password can immediately obtain a persistent, privileged foothold on the robot via the undocumented backdoor. With that foothold the attacker can read sensitive telemetry and internal state, run arbitrary commands as root, and install or restore components that survive reboots and firmware updates.

When combined with the hardcoded credential described in CVE-2026-7414, an attacker has effectively unfettered access to the target robot, across the internet. When combined with CVE-2026-7415 (open MQTT orchestration) the attacker can locate specific robots to target with this vulnerability. In short, these issues together allow trivial unauthorized persistent control, fleet-wide compromise, and widespread data exposure.

See Bin4ry’s original disclosure details at Yarbo - NAT in my Back Yard .

Reported by Andreas Makris (aka Bin4ry), demonstrated and disclosed through AHA! .