news.mlab.sh
Back to the feed
threat-intel

Yarbo Android/iOS Mobile Application and Cloud Infrastructure

High
Summary

A CISA advisory details a vulnerability in the Yarbo Android/iOS Mobile Application and Cloud Infrastructure, specifically related to hard-coded MQTT credentials. The application contains credentials that allow unauthorized access to telemetry data from the global Yarbo robot fleet and the ability to issue commands to individual robots. This poses a significant risk to commercial facilities worldwide due to the lack of per-device or per-user authorization.

The vulnerability stems from the inclusion of identical, hard-coded MQTT broker credentials within the Yarbo Android and iOS mobile applications. These credentials, readily accessible through APK decompilation, grant access to the cloud MQTT brokers that transmit real-time telemetry data from the entire global Yarbo robot fleet. Attackers could utilize these credentials to subscribe to all robot telemetry topics and publish commands to any robot using only its serial number. The lack of proper authorization controls exacerbates the risk, allowing a single compromised credential to provide fleet-wide access. Yarbo has released version 3.17.4 of the mobile application to address this issue, and server-side broker authorization will be enforced automatically upon deployment of the May 2026 update.

Read the full article at CISA Advisories