PT-2026-48886 · Yarbo · Yarbo Cloud
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Yarbo cloud (affected versions not specified)
Description
The cloud service fails to enforce per-device or per-user authorization. A client with valid credentials, including shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics that cover all robots globally. Additionally, an attacker can publish to any robot's command topic by using the robot's serial number, which is disclosed in the telemetry stream. This lack of per-device access controls allows a single compromised credential to provide fleet-wide access.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yarbo Cloud