AHA! has discovered an issue affecting Yarbo robot firmware v2.3.9. This disclosure follows AHA!’s standard disclosure policy . Any questions this disclosure should be directed to [email protected] .
Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them.
This vulnerability is estimated to have a CVSSv31 rating of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8, Critical) and the relevant SSVC vectors are Exploitation: PoC and Technical Impact: Total . This issue is an instance of CWE-798 .
Static username and password credentials are embedded in configuration files and binaries within the firmware image. These credentials grant administrative access to the device’s SSH and management interfaces. Attempts to change credentials via the device UI are reverted on reboot, as the original values are restored from a read-only firmware partition.
An attacker who knows the hardcoded credentials — which are shared across every device running this firmware — can immediately authenticate to any affected robot’s management interface without any prior access or exploitation. This is the key that unlocks CVE-2026-7413: the undocumented backdoor SSH service described there accepts these same credentials, providing a root shell to anyone on the internet who reaches the device through the NAT-punching proxy. When combined with CVE-2026-7415, the open MQTT broker can be used to enumerate devices on the network, giving an attacker a target list to attack at scale with these credentials. The result is mass, unauthenticated, persistent compromise of an entire fleet.
See Bin4ry’s original disclosure details at Yarbo - NAT in my Back Yard .
Reported by Andreas Makris (aka Bin4ry), demonstrated and disclosed through AHA! .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
