Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 14 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yarbo lawn Mower
Yarbo lawn Mower Firmware Yarbo lawn Mower Pro Yarbo lawn Mower Pro Firmware |
|
| CPEs | cpe:2.3:h:yarbo:lawn_mower:-:*:*:*:*:*:*:* cpe:2.3:h:yarbo:lawn_mower_pro:-:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_firmware:2.3.9:*:*:*:*:*:*:* cpe:2.3:o:yarbo:lawn_mower_pro_firmware:2.3.9:*:*:*:*:*:*:* |
|
| Vendors & Products |
Yarbo lawn Mower
Yarbo lawn Mower Firmware Yarbo lawn Mower Pro Yarbo lawn Mower Pro Firmware |
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yarbo
Yarbo firmware |
|
| Vendors & Products |
Yarbo
Yarbo firmware |
Thu, 07 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind. | |
| Title | Open MQTT orchestration without read/write ACLs in Yarbo robot firmware | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2026-05-07T17:04:31.177Z
Reserved: 2026-04-29T13:55:11.141Z
Link: CVE-2026-7415
Updated: 2026-05-07T17:03:31.152Z
Status : Analyzed
Published: 2026-05-07T17:15:59.570
Modified: 2026-05-14T17:50:35.057
Link: CVE-2026-7415
No data.
OpenCVE Enrichment
Updated: 2026-05-07T21:24:35Z