CVE-2026-7415General(yarbo / lawn_mower)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lawn_mower
  • lawn_mower_firmware
  • lawn_mower_pro
  • lawn_mower_pro_firmware

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-14)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
lawn_mowerlawn_mower_firmwarelawn_mower_prolawn_mower_pro_firmware

2 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-07: 1Mentions · 2026-05-14: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 105-0705-14
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-142
General2
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-7415 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The tweet references CVE-2026-7415 with its CVSS score and critical severity, but provides no exploitation or patch information.

    1001039
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7415-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text contains only a link and generic hashtags, offering no concrete details about the CVE.

    0000020
    210 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical flaws CVE-2026-7413, CVE-2026-7414 and CVE-2026-7415 in Yarbo robot firmware v2.3.9 expose a hidden backdoor, hardcoded admin creds and open MQTT control for remote takeover. https://threatcluster.io/cluster/critical-vulnerabilities-in-yarbo-robot-firmware-expose-devi-a8214e72

    Post summary

    Three critical CVEs in Yarbo robot firmware v2.3.9 expose a hidden backdoor, hardcoded admin credentials, and open MQTT control, allowing remote takeover.

    0000073
    198 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWyarbolawn_mower---
OSyarbolawn_mower_firmware2.3.9--
HWyarbolawn_mower_pro---
OSyarbolawn_mower_pro_firmware2.3.9--

Explore more