CVE-2026-7413
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.58%
- CWE
- CWE-912
- Published
- 2026-05-07
- Last modified
- 2026-05-08
Affected products
- Yarbo Firmware
Weakness type
Related vulnerabilities
- CVE-2026-18844 — Pulsetto Vagus Nerve Stimulator Hidden Functionality
- CVE-2026-61515 — Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
- CVE-2026-18191 — Vacron|IP Camera - Hidden Functionality
- CVE-2026-4769 — Unauthenticated Access to Internal Diagnostic Interface
- CVE-2026-41446 — WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
- CVE-2026-1952 — Denial of service via the undocumented subfunction in AS320T
- CVE-2026-34769 — Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
- CVE-2026-4621 — Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable...