Junglewise Threat Intelligence

CVE-2026-7413: Yarbo Lawn Mower firmware persistent backdoor in SSH service

CVE-2026-7413 · Severity: high · CVSS 7.2 · Published 2026-05-07

Technologies: Yarbo Lawn Mower Pro, Yarbo Lawn Mower Firmware, Yarbo Lawn Mower, Yarbo Lawn Mower Pro Firmware. Vendors: Yarbo.

Executive brief

A hidden backdoor was discovered in Yarbo smart lawn mower robots that allows unauthorized remote access to the device's core operating system. An attacker can exploit this to take full control of the robot, access sensitive camera or location data, and disrupt operations. This backdoor is designed to survive factory resets and standard updates, making it difficult for users to remove without official vendor intervention.

Technical details

An undocumented SSH service (CWE-912) is present in Yarbo firmware v2.3.9, listening on all affected devices and reachable via a NAT-punching proxy system. The service provides an interactive shell with root privileges. Because the component is restored during the normal boot process, the backdoor is persistent across factory resets and standard firmware updates. While some assessments suggest high privileges are required, NVD analysis indicates the vulnerability is reachable over the network without authentication, leading to a total compromise of confidentiality, integrity, and availability. When combined with other vulnerabilities like hardcoded credentials, it allows for fleet-wide remote command execution.

Affected products

  • Yarbo Lawn Mower firmware 2.3.9
  • Yarbo Lawn Mower Pro firmware 2.3.9

Timeline

  • 2026-04-12: other: Initial outreach to vendor
  • 2026-04-29: other: CVE reserved
  • 2026-05-07: disclosed: Public disclosure
  • 2026-05-07: advisory

References

Related threats