CVE-2026-7414Disclosure(yarbo / lawn_mower)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lawn_mower
  • lawn_mower_firmware
  • lawn_mower_pro
  • lawn_mower_pro_firmware

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-14)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
lawn_mowerlawn_mower_firmwarelawn_mower_prolawn_mower_pro_firmware

2 versions affected across 4 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-07: 1Mentions · 2026-05-14: 4Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 305-0705-14
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-144
Disclosure2General2
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-7414 (CVSS 9.8) — multiple products. CVE: CVE-2026-7414 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a newly identified critical vulnerability (CVE-2026-7414) with its CVSS score and severity, but contains no PoC, exploit tools, active exploitation claim, patch, or false‑positive statement.

    1001037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-7414 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory lists CVE-2026-7414 with its CVSS score and severity but offers no additional exploitation, patch, or mitigation details.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7414 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image.

    Post summary

    The advisory reveals a critical hardcoded credential vulnerability in Yarbo firmware v2.3.9, with no evidence of exploitation, PoC, or mitigation steps in the text.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7414-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The excerpt merely references a URL and hashtags without providing detailed information on the CVE.

    0000025
    210 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical flaws CVE-2026-7413, CVE-2026-7414 and CVE-2026-7415 in Yarbo robot firmware v2.3.9 expose a hidden backdoor, hardcoded admin creds and open MQTT control for remote takeover. https://threatcluster.io/cluster/critical-vulnerabilities-in-yarbo-robot-firmware-expose-devi-a8214e72

    Post summary

    Critical flaws CVE‑2026‑7413, CVE‑2026‑7414, and CVE‑2026‑7415 in Yarbo robot firmware expose a hidden backdoor, hardcoded admin credentials, and an open MQTT interface, enabling potential remote takeover. The announcement highlights the severity and detail of these vulnerabilities.

    0000073
    198 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWyarbolawn_mower---
OSyarbolawn_mower_firmware2.3.9--
HWyarbolawn_mower_pro---
OSyarbolawn_mower_pro_firmware2.3.9--

Explore more