CVE-2026-7413 PUBLISHED

Persistent undocumented backdoor access in Yarbo robot

Assigner: AHA
Reserved: 29.04.2026 Published: 07.05.2026 Updated: 07.05.2026

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Yarbo
Product Firmware
Versions Default: unaffected
  • affected from 0 to 2.3.9 (incl.)

Credits

  • Andreas Makris (aka Bin4ry) finder
  • todb of AHA! coordinator

References

Problem Types

  • CWE-912 Hidden Functionality CWE