A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.
References
| Link | Resource |
|---|---|
| https://github.com/Bin4ry/yarbo-nat-in-my-back-yard | Exploit Third Party Advisory |
| https://takeonme.org/gcves/GCVE-1337-2026-00000000000000000000000000000000000000000000000000111111111111111111111110000000000000000000000000000000000000000000000000000000111 | Third Party Advisory |
| https://takeonme.org/cves/cve-2026-7413/ | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-05-07 17:15
Updated : 2026-06-17 11:02
NVD link : CVE-2026-7413
Mitre link : CVE-2026-7413
CVE.ORG link : CVE-2026-7413
JSON object : View
Products Affected
yarbo
- lawn_mower_firmware
- lawn_mower
- lawn_mower_pro_firmware
- lawn_mower_pro
CWE
