A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.
Metrics
Affected Vendors & Products
References
History
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yarbo
Yarbo firmware |
|
| Vendors & Products |
Yarbo
Yarbo firmware |
Thu, 07 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates. | |
| Title | Persistent undocumented backdoor access in Yarbo robot | |
| Weaknesses | CWE-912 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2026-05-07T16:09:26.134Z
Reserved: 2026-04-29T13:37:07.749Z
Link: CVE-2026-7413
No data.
Status : Awaiting Analysis
Published: 2026-05-07T17:15:59.343
Modified: 2026-05-07T18:46:25.867
Link: CVE-2026-7413
No data.