A researcher found that Yarbo yard robots came with a host of vulnerabilities which, among others, allowed an attacker to harvest WiFi passwords. Security researcher Andreas Makris found he could remotely hijack thousands of Yarbo yard robots worldwide, and proved it by having his mower run him over. The root cause was a cluster of “legacy” design choices: every robot shared the same hardcoded root password, remote tunnels were left open, and Message Queuing Telemetry Transport (MQTT) messaging was so weakly protected that once you had one device, you effectively had the worldwide fleet. An attacker could pull GPS coordinates, email addresses, and Wi‑Fi passwords, turn cameras into remote spying tools, and even re‑arm the mower after someone hit the emergency stop. All of this was enabled by a persistent backdoor tunnel that users could neither see nor meaningfully control. The risks fell into three very different buckets: - A heavy mower with remotely controllable blades and an emergency stop that can be bypassed is a real-world safety hazard. - Exposed telemetry meant attackers could map where devices were, see who owned them, and in some reports even view camera feeds. - Network abuse through shared root credentials meant compromised robots could scan local networks, steal more data, or be folded into a botnet. Yarbo’s public response is unusually detailed for a consumer Internet of Things (IoT) vendor. It’s also refreshingly blunt in admitting that the researcher’s core findings were accurate. The company temporarily disabled the remote diagnostic tunnels, reset root passwords, locked down unauthenticated endpoints, and began ripping out unnecessary legacy access paths. More importantly, Yarbo promises structural changes: - Unique per‑device credentials. - Over-the-Air (OTA) credential rotation. - Audited, allowlist‑based remote diagnostics. - Dedicated security contact, with a possible bug bounty to follow. That is the sort of
Yarbo responds to robot flaws that could mow down their owners
Read the original article
malwarebytes.com →