Executive brief
Yarbo smart lawn mowers contain permanent, factory-set administrative passwords that are identical across all devices. An attacker who knows these credentials can remotely access and control the mower's management interface. This could lead to unauthorized operation of the device, changes to its configuration, or complete loss of control for the owner.
Technical details
A use of hard-coded credentials (CWE-798) exists in Yarbo firmware version 2.3.9. The firmware image contains static administrative credentials that are shared across the entire product line and cannot be modified or deleted by the end user. An attacker with network access to the device's management interface can use these credentials to gain full administrative privileges. This vulnerability was identified through static analysis of the Android APK and filesystem dumps from physical robot hardware. No patch has been reported in the advisory.
Affected products
- Yarbo Lawn Mower firmware 2.3.9
- Yarbo Lawn Mower Pro firmware 2.3.9
Timeline
- 2026-05-07: disclosed: Vulnerability reported by Andreas Makris via Austin Hackers Anonymous.
- 2026-05-07: advisory: CVE-2026-7414 published.