Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-10557— Yarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-coded Credentials

Quick assessment

Affected
Yarbo Yarbo Android/IOS mobile application
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Yarbo Mobile Application是美国Yarbo公司的一款用于管理和控制智能庭院机器人设备的移动应用。 Yarbo Mobile Application存在信任管理问题漏洞,该漏洞源于包含硬编码的MQTT代理凭据,这些凭据对所有用户和设备相同,可通过APK反编译提取,可能导致未经授权的访问整个Yarbo机器人车队实时遥测数据以及向任意机器人发送命令。

CVSS 9.8 · Critical EPSS 0.35% · P29

Affected Version Matrix 2

VendorProduct Version RangeStatus
Yarbo Yarbo Android/IOS mobile application < 3.17.4 affected
Yarbo Yarbo Cloud MQTT infrastructure All affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10557

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Yarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-coded Credentials
Source: CVE Program / CVE List V5
Vulnerability Description
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the robot's serial number.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5
Vulnerability Title
Yarbo Mobile Application 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Yarbo Mobile Application是美国Yarbo公司的一款用于管理和控制智能庭院机器人设备的移动应用。 Yarbo Mobile Application存在信任管理问题漏洞,该漏洞源于包含硬编码的MQTT代理凭据,这些凭据对所有用户和设备相同,可通过APK反编译提取,可能导致未经授权的访问整个Yarbo机器人车队实时遥测数据以及向任意机器人发送命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Yarbo Yarbo Android/IOS mobile application 0 ~ 3.17.4 -
Yarbo Yarbo Cloud MQTT infrastructure All -

II. Public POCs for CVE-2026-10557

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10557

登录查看更多情报信息。

Vendor Advisories for CVE-2026-10557 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-10557

No comments yet


Leave a comment