Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them.
References
| Link | Resource |
|---|---|
| https://github.com/Bin4ry/yarbo-nat-in-my-back-yard | Exploit Third Party Advisory |
| https://takeonme.org/gcves/GCVE-1337-2026-00000000000000000000000000000000000000000000000001111111111100011111111111000000000000000000000000000000000000000000000000000001000 | Third Party Advisory |
| https://github.com/Bin4ry/yarbo-nat-in-my-back-yard#3--hardcoded-developer-credentials-in-production-apk | Exploit Third Party Advisory |
Configurations
History
14 May 2026, 17:53
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Yarbo lawn Mower Pro Firmware
Yarbo lawn Mower Pro Yarbo Yarbo lawn Mower Firmware Yarbo lawn Mower |
|
| CPE | cpe:2.3:h:yarbo:lawn_mower_pro:-:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_firmware:2.3.9:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_pro_firmware:2.3.9:*:*:*:*:*:*:* cpe:2.3:h:yarbo:lawn_mower:-:*:*:*:*:*:*:* |
|
| References | () https://github.com/Bin4ry/yarbo-nat-in-my-back-yard - Exploit, Third Party Advisory | |
| References | () https://takeonme.org/gcves/GCVE-1337-2026-00000000000000000000000000000000000000000000000001111111111100011111111111000000000000000000000000000000000000000000000000000001000 - Third Party Advisory | |
| References | () https://github.com/Bin4ry/yarbo-nat-in-my-back-yard#3--hardcoded-developer-credentials-in-production-apk - Exploit, Third Party Advisory |
07 May 2026, 18:46
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 17:15
Updated : 2026-05-14 17:53
NVD link : CVE-2026-7414
Mitre link : CVE-2026-7414
CVE.ORG link : CVE-2026-7414
JSON object : View
Products Affected
yarbo
- lawn_mower_pro_firmware
- lawn_mower_firmware
- lawn_mower_pro
- lawn_mower
CWE
CWE-798
Use of Hard-coded Credentials
