CVE-2026-10557

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the robot's serial number.
Configurations

No configuration.

History

12 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 15:16

Updated : 2026-06-12 16:06


NVD link : CVE-2026-10557

Mitre link : CVE-2026-10557

CVE.ORG link : CVE-2026-10557


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials