← Retour à la recherche de CVE

CVE-2026-7368

Yarbo cloud

Description

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot-s command topic using only the robot-s serial number (disclosed in the telemetry stream). Even after removal of hard-coded credentials from the app, a single compromised credential could still provide fleet-wide access without per-device access controls.

CVSS 8.1EPSS 0.259%Risque 0.83
Voir la source
Publication
2026-06-12 15:16:32
Versions concernées
unknown
Type
Autre
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N