Junglewise Threat Intelligence

CVE-2026-7414: Yarbo Lawn Mower hardcoded credentials in firmware

CVE-2026-7414 · Severity: critical · CVSS 9.8 · Published 2026-05-07

Technologies: Yarbo Lawn Mower Pro, Yarbo Lawn Mower Firmware, Yarbo Lawn Mower, Yarbo Lawn Mower Pro Firmware. Vendors: Yarbo.

Executive brief

Yarbo smart lawn mowers contain permanent, factory-set administrative passwords that are identical across all devices. An attacker who knows these credentials can remotely access and control the mower's management interface. This could lead to unauthorized operation of the device, changes to its configuration, or complete loss of control for the owner.

Technical details

A use of hard-coded credentials (CWE-798) exists in Yarbo firmware version 2.3.9. The firmware image contains static administrative credentials that are shared across the entire product line and cannot be modified or deleted by the end user. An attacker with network access to the device's management interface can use these credentials to gain full administrative privileges. This vulnerability was identified through static analysis of the Android APK and filesystem dumps from physical robot hardware. No patch has been reported in the advisory.

Affected products

  • Yarbo Lawn Mower firmware 2.3.9
  • Yarbo Lawn Mower Pro firmware 2.3.9

Timeline

  • 2026-05-07: disclosed: Vulnerability reported by Andreas Makris via Austin Hackers Anonymous.
  • 2026-05-07: advisory: CVE-2026-7414 published.

References

Related threats