216.73.216.133

CVE-2026-10557

· Published 12/06/2026 17:16 · Modified 12/06/2026 16:06 · Author: The MITRE Corporation

Labels: CVE-2026-10557 2026-06-12CVE-2026-10557CWE-798[email protected]

Essential information

Published
12/06/2026 17:16
Modified
12/06/2026 16:06
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.8 CRITICAL (v3.1) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CWE-798
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the robot's serial number.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
yarbo / yarbo application cpe:2.3:a:yarbo:yarbo_application:*:*:*:*:*:*:*:*

References