A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.
References
| Link | Resource |
|---|---|
| https://github.com/Bin4ry/yarbo-nat-in-my-back-yard | Exploit Third Party Advisory |
| https://takeonme.org/gcves/GCVE-1337-2026-00000000000000000000000000000000000000000000000000111111111111111111111110000000000000000000000000000000000000000000000000000000111 | Third Party Advisory |
| https://takeonme.org/cves/cve-2026-7413/ | Third Party Advisory |
Configurations
History
14 May 2026, 17:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Bin4ry/yarbo-nat-in-my-back-yard - Exploit, Third Party Advisory | |
| References | () https://takeonme.org/gcves/GCVE-1337-2026-00000000000000000000000000000000000000000000000000111111111111111111111110000000000000000000000000000000000000000000000000000000111 - Third Party Advisory | |
| References | () https://takeonme.org/cves/cve-2026-7413/ - Third Party Advisory | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:h:yarbo:lawn_mower_pro:-:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_firmware:2.3.9:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_pro_firmware:2.3.9:*:*:*:*:*:*:* cpe:2.3:h:yarbo:lawn_mower:-:*:*:*:*:*:*:* |
|
| First Time |
Yarbo lawn Mower Pro Firmware
Yarbo lawn Mower Pro Yarbo Yarbo lawn Mower Firmware Yarbo lawn Mower |
08 May 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 May 2026, 18:46
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 17:15
Updated : 2026-05-14 17:54
NVD link : CVE-2026-7413
Mitre link : CVE-2026-7413
CVE.ORG link : CVE-2026-7413
JSON object : View
Products Affected
yarbo
- lawn_mower_pro_firmware
- lawn_mower_firmware
- lawn_mower_pro
- lawn_mower
CWE
