Thousands of internet-connected Yarbo robotic lawnmowers were exposed to remote compromise after researcher Andreas Makris found identical default administrator credentials across the fleet, enabling access to owner email addresses, Wi-Fi passwords, and precise GPS locations. Reports said more than 11,000 devices in over 30 countries were reachable, and a live demonstration showed a 200-pound mower outside a family home in New York being remotely controlled from Germany, raising concerns that attackers could override local controls, activate blades, or use onboard cameras for surveillance.
Makris' published research alleged the problem extended beyond shared passwords to a broader remote-access architecture, including fleet-wide root SSH access through FRP NAT traversal tunnels, shared MQTT credentials, an unauthenticated robot-shadow API exposing device state and location by serial number, and plaintext developer credentials in production mobile apps. Yarbo said it disabled remote diagnostic tunnels, reset root passwords, and moved to device-specific credentials, but researchers warned that retained manufacturer remote access could still function like a backdoor and leave the Linux-based devices usable for botnets, network intrusion, or attacks near sensitive sites such as critical infrastructure.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
Following the disclosure, Yarbo said it disabled remote diagnostic tunnels, reset root passwords, and moved to device-specific credentials. Researchers said these steps did not fully resolve concerns because manufacturer remote access allegedly remained possible.
As part of the public disclosure reported on 2026-05-15, Makris demonstrated remote control of a 200-pound Yarbo mower in upstate New York from Germany. The demonstration showed an outsider could override local controls and potentially abuse onboard cameras and other connected features.
By 2026-05-15, reporting on Makris's findings said thousands of Yarbo robotic lawnmowers worldwide were remotely compromisable because they used identical default administrator credentials. The disclosure said more than 11,000 exposed devices were mapped across over 30 countries and that sensitive data including owner email addresses, Wi-Fi passwords, and precise GPS locations could be accessed.
On 2026-05-11, Yarbo said it would completely remove the intentional remote backdoor from its robots after public security concerns. The company said any future remote diagnostic capability would instead be an optional opt-in feature for customers.
On 2026-05-07, security researcher Andreas Makris published a report alleging Yarbo autonomous lawn and snow robots exposed fleet-wide root SSH access through FRP NAT traversal tunnels, a hardcoded root password, shared MQTT credentials, and an unauthenticated API leaking device state and GPS data. The report estimated roughly 6,000 affected robots and warned of risks including unauthorized robot control, camera access, Wi-Fi credential theft, and lateral movement into local networks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
10 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcekaspersky.ru
Open sourcecysecurity.news
Open sourcescworld.com
Open sourcegithub.com
Open sourceeu.yarbo.com
Open sourceeu.yarbo.com
Open sourceforum.yarbo.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.