Impact
The vulnerability lies in the absence of per-device or per-user authorization within the Yarbo cloud infrastructure. Because any client with valid credentials can subscribe to a global wildcard topic and publish to any robot’s command topic using just the robot’s serial number, an attacker can issue operational commands to any robot in the fleet. This enables remote command execution on all connected devices and can compromise the integrity and confidentiality of the robotic systems.
Affected Systems
The affected products are the Yarbo mobile application for Android and iOS, and the Yarbo Cloud MQTT broker that serves those clients. All versions before 3.17.4 of the mobile app are impacted, as are broker deployments that have not yet received the May 2026 update that introduces mandatory per‑device authorization.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity. While the EPSS score is not available, the risk is elevated because the attack requires only valid credentials, which can be obtained by stealing or guessing the hard‑coded or shared credentials. The vulnerability is not listed in KEV, but once compromised it allows an attacker to control any robot remotely via MQTT. The issue is mapped to CWE‑862, Authentication Failure.
OpenCVE Enrichment