Hardcoded credentials in Yarbo robot firmware
Summary
| CVE | CVE-2026-7414 |
|---|---|
| State | PUBLISHED |
| Assigner | AHA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-07 17:15:59 UTC |
| Updated | 2026-05-14 17:53:31 UTC |
| Description | Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.000180000 probability, percentile 0.048280000 (date 2026-05-25)
Problem Types: CWE-798 | CWE-798 CWE-798 Use of Hard-coded Credentials
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Yarbo | Lawn Mower | - | All | All | All |
| Operating System | Yarbo | Lawn Mower Firmware | 2.3.9 | All | All | All |
| Hardware | Yarbo | Lawn Mower Pro | - | All | All | All |
| Operating System | Yarbo | Lawn Mower Pro Firmware | 2.3.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/Bin4ry/yarbo-nat-in-my-back-yard | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | Exploit, Third Party Advisory |
| github.com/Bin4ry/yarbo-nat-in-my-back-yard | [email protected] | github.com | Exploit, Third Party Advisory |
| takeonme.org/gcves/GCVE-1337-2026-0000000000000000000000000000000000000000... | [email protected] | takeonme.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andreas Makris (aka Bin4ry) (en)
CNA: todb of AHA! (en)
There are currently no legacy QID mappings associated with this CVE.