The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind.
Metrics
Affected Vendors & Products
References
History
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yarbo
Yarbo firmware |
|
| Vendors & Products |
Yarbo
Yarbo firmware |
Thu, 07 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind. | |
| Title | Open MQTT orchestration without read/write ACLs in Yarbo robot firmware | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2026-05-07T17:04:31.177Z
Reserved: 2026-04-29T13:55:11.141Z
Link: CVE-2026-7415
Updated: 2026-05-07T17:03:31.152Z
Status : Awaiting Analysis
Published: 2026-05-07T17:15:59.570
Modified: 2026-05-07T18:46:25.867
Link: CVE-2026-7415
No data.
OpenCVE Enrichment
Updated: 2026-05-07T21:24:35Z