CVE 9.8 CRITICAL

Hardcoded credentials in Yarbo robot firmware_CVE-2026-7414

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them.

AI Analysis

Hardcoded administrative credentials in Yarbo firmware enable unauthorized access

Basic Information

ID CVE-2026-7414
Source AHA
Published May 7, 2026 at 16:10
Modified May 7, 2026 at 17:01

Affected Product

Vendor Yarbo
Product Firmware
Affected Versions Yarbo Firmware 0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Yarbo
Product Yarbo Robot Firmware
Version v2.3.9

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.