PT-2026-48876 · Yarbo · Yarbo
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Yarbo Android and iOS applications (affected versions not specified)
Description
The Android and iOS applications contain hard-coded MQTT broker credentials that are identical across all users and devices. These credentials, embedded in the application binary, can be extracted through APK decompilation. This allows unauthorized access to cloud MQTT brokers that handle real-time telemetry for the global robot fleet. An attacker can use these credentials to perform wildcard subscriptions to all robot telemetry topics or publish messages to any robot's command topic by providing the robot's serial number.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yarbo