Vulnerability Description
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the robot's serial number.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-16
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-01
FAQ
What is CVE-2026-10557?
CVE-2026-10557 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are rea...
How severe is CVE-2026-10557?
CVE-2026-10557 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-10557?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.