PT-2026-48876 · Yarbo · Yarbo

·

CVE-2026-10557

·

Published

2026-06-12

·

Updated

2026-06-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yarbo Android and iOS applications (affected versions not specified)
Description The Android and iOS applications contain hard-coded MQTT broker credentials that are identical across all users and devices. These credentials, embedded in the application binary, can be extracted through APK decompilation. This allows unauthorized access to cloud MQTT brokers that handle real-time telemetry for the global robot fleet. An attacker can use these credentials to perform wildcard subscriptions to all robot telemetry topics or publish messages to any robot's command topic by providing the robot's serial number.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10557

Affected Products

Yarbo