# Hard-Coded Cloud Credentials Expose Thousands of Yarbo Robots to Fleet-Wide Command Injection


## The Threat


Yarbo's Android and iOS mobile applications contain hard-coded MQTT broker credentials embedded directly in the application binaries—shared across every device globally and trivially extractable through APK decompilation. These identical credentials grant unrestricted access to the company's cloud infrastructure, allowing attackers to monitor real-time telemetry from thousands of robotic devices worldwide and send arbitrary operational commands to the entire fleet using only a robot's publicly disclosed serial number.


The vulnerabilities represent a cascading failure in architectural security. The first flaw—hard-coded credentials—is a preventable design mistake common in early-stage IoT development but catastrophic when deployed at scale. The second and more critical issue is the complete absence of per-device and per-user authorization controls in the cloud MQTT infrastructure. Even after Yarbo removes hard-coded credentials, the underlying authorization framework remains fundamentally broken: any legitimate user credential compromised through phishing, malware, or insider threat would still provide unfettered access to the global robot fleet.


The implications extend beyond simple reconnaissance. An attacker with cloud access can monitor where robots are deployed, their operational status, and their movement patterns—potentially exposing commercial and industrial facility layouts. More critically, the ability to publish commands to any robot's topic means attackers can trigger unintended operations, potentially disrupting manufacturing lines, logistics operations, or any commercial facility relying on Yarbo's equipment. This is not a passive data leak; it is active remote control of potentially thousands of physical devices in critical infrastructure environments.


## Severity and Impact


| Aspect | Details |

|--------|---------|

| CVE-2026-10557 | Hard-Coded MQTT Credentials |

| CVE-2026-7368 | Missing Authorization Controls |

| CVSS v3.1 Score | 9.8 (CRITICAL) / 8.1 (HIGH) |

| CVSS v4.0 Score | 9.3 (CRITICAL) / 8.6 (HIGH) |

| CVSS v3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVE-2026-10557) |

| CVSS v3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N (CVE-2026-7368) |

| Attack Vector | Network (MQTT protocol) |

| Attack Complexity | Low |

| Privileges Required | None (CVE-2026-10557) / Low (CVE-2026-7368) |

| CWE-798 | Use of Hard-Coded Credentials |

| CWE-862 | Missing Authorization |

| Reporter | Markus Lassfolk, Truesec |


## Affected Products


Yarbo Android/iOS Mobile Application:

  • Versions prior to 3.17.4 (all earlier versions affected)

  • Yarbo Cloud MQTT Infrastructure:

  • All current versions (vulnerable to authorization bypass)

  • Both vulnerabilities require coordinated remediation: application updates alone are insufficient without corresponding cloud-side authorization enforcement.


    ## Mitigations


    Immediate Actions for Organizations:


    1. Update Mobile Applications – Deploy Yarbo mobile app version 3.17.4 or later to all devices. Users should prioritize this update immediately to prevent credential extraction.


    2. Expect Cloud-Side Authorization – Yarbo will automatically enforce per-device and per-user authorization controls via a May 2026 server update. No manual user configuration is required, but organizations should verify authorization is active once the update deploys.


    3. Network Segmentation – Restrict MQTT broker access to authorized internal networks. Do not expose robot control systems directly to the internet. Place all Yarbo devices and controllers behind firewalls with explicit allow-lists.


    4. Monitor Telemetry Access – Review MQTT broker logs for unexpected subscriptions or command publications. Track which credentials are accessing which robot topics and alert on anomalies.


    5. Credential Review – If your organization uses Yarbo infrastructure with legitimate per-user credentials, assume those credentials may be compromised and plan for rotation once per-device authorization is enforced.


    6. Operational Continuity Planning – For facilities where Yarbo robots are mission-critical, develop contingency procedures in case of unauthorized commands. Establish manual override protocols and staff training for emergency operations.


    ## References


  • CISA Advisory: Hard-Coded Credentials and Missing Authorization in Yarbo Mobile and Cloud Infrastructure
  • CVE-2026-10557: https://nvd.nist.gov/ (Hard-Coded MQTT Credentials)
  • CVE-2026-7368: https://nvd.nist.gov/ (Missing Authorization)
  • Truesec Research: Vulnerability report and technical analysis
  • Yarbo Security Advisory: Official remediation guidance and update timeline

  • ---


    ## HackWire Analysis


    This vulnerability pair illustrates a pervasive architectural anti-pattern in connected device ecosystems: the assumption that keeping credentials secret is an adequate substitute for proper access controls. Yarbo's engineers embedded shared credentials as a shortcut to enable mobile app connectivity without implementing credential-per-device provisioning—a decision that works fine at 100 devices but becomes a liability at thousands. The hard-coded credentials are the headline, but the real systemic failure is the missing authorization layer beneath them.


    What makes this particularly dangerous is that it's not a zero-day waiting to be discovered in the wild. These vulnerabilities sit in plain sight: the credentials are trivially extractable from any APK, and the MQTT broker accepts commands from anyone who possesses them. Threat actors monitoring APK release repositories likely already have access. For any facility deploying Yarbo robots, the assumption should be that unauthorized parties can subscribe to all telemetry and issue commands—and operations should be hardened against that threat model immediately, not after May.


    The remediation timeline is also concerning. Yarbo is not asking users to do anything—updates will "be enforced automatically." This passive approach leaves a multi-month window where the cloud infrastructure remains fundamentally broken. Organizations relying on Yarbo robots should not wait; they should preemptively network-segment their robot infrastructure, rotate any legitimate credentials, and monitor for suspicious MQTT activity starting now. The pattern here matches earlier IoT waves: mass deployment of convenience-first devices, followed by discovery of systemic architecture flaws, followed by a scramble to retrofit security after the fact. Yarbo's scale means that scramble affects thousands of commercial facilities globally.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)