Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 14 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yarbo lawn Mower
Yarbo lawn Mower Firmware Yarbo lawn Mower Pro Yarbo lawn Mower Pro Firmware |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:yarbo:lawn_mower:-:*:*:*:*:*:*:* cpe:2.3:h:yarbo:lawn_mower_pro:-:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_firmware:2.3.9:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_pro_firmware:2.3.9:*:*:*:*:*:*:* |
|
| Vendors & Products |
Yarbo lawn Mower
Yarbo lawn Mower Firmware Yarbo lawn Mower Pro Yarbo lawn Mower Pro Firmware |
Fri, 08 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yarbo
Yarbo firmware |
|
| Vendors & Products |
Yarbo
Yarbo firmware |
Thu, 07 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates. | |
| Title | Persistent undocumented backdoor access in Yarbo robot | |
| Weaknesses | CWE-912 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2026-05-08T22:46:29.192Z
Reserved: 2026-04-29T13:37:07.749Z
Link: CVE-2026-7413
Updated: 2026-05-08T22:46:22.450Z
Status : Analyzed
Published: 2026-05-07T17:15:59.343
Modified: 2026-05-14T17:54:50.453
Link: CVE-2026-7413
No data.
OpenCVE Enrichment
Updated: 2026-05-14T20:00:14Z