Skip to content
Cve 2026 7415

Cve 2026 7415

takeonme.org • May 7, 2026

AHA! has discovered an issue affecting Yarbo robot firmware v2.3.9. This disclosure follows AHA!’s standard disclosure policy . Any questions this disclosure should be directed to [email protected] .

This vulnerability is estimated to have a CVSSv31 rating of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8, Critical) and the relevant SSVC vectors are Exploitation: PoC and Technical Impact: Total . This issue is an instance of CWE-306 .

An attacker on the local network, or reaching the device through the NAT-punching proxy referenced in CVE-2026-7413, can use the open MQTT broker to passively enumerate active robots, read live telemetry, and identify specific devices to target. More critically, they can actively publish commands to control robot actuators or alter configurations, with no credentials required. When chained with CVE-2026-7413 and CVE-2026-7414, this open broker completes a fully unauthenticated attack path: MQTT reveals and enumerates devices, hardcoded credentials provide authenticated management access, and the persistent backdoor delivers a root shell — all without the attacker needing to perform any exploitation in the traditional sense.

See Bin4ry’s original disclosure details at Yarbo - NAT in my Back Yard .

Reported by Andreas Makris (aka Bin4ry), demonstrated and disclosed through AHA! .