Project Subscriptions
No data.
No advisories yet.
Solution
Yarbo recommends users update the Yarbo mobile app to 3.17.4 or later. Server-side broker authorization will be enforced automatically upon deployment of the May 2026 update. No user action is required.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the robot's serial number. | |
| Title | Yarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-12T15:35:50.875Z
Reserved: 2026-06-01T14:53:33.531Z
Link: CVE-2026-10557
Updated: 2026-06-12T15:35:39.975Z
Status : Deferred
Published: 2026-06-12T15:16:24.523
Modified: 2026-06-12T16:06:47.720
Link: CVE-2026-10557
No data.
OpenCVE Enrichment
Updated: 2026-06-12T15:30:31Z