CVE-2026-10557: Hard‑coded MQTT credentials expose Yarbo robot telemetry and commands

Originally published at: CVE-2026-10557: Hard‑coded MQTT credentials expose Yarbo robot telemetry and commands - ToolsLib Blog

CVE-2026-10557 details hard‑coded, shared MQTT credentials in Yarbo’s mobile apps that expose fleet‑wide robot telemetry and enable command publishing using only a serial number. CISA rates it Critical (CVSS 9.8). Here’s what’s confirmed, why it matters, and prudent steps until vendor guidance arrives.