Sunday, May 10, 2026
35.1 C
New Delhi

Risky robots: German researcher exposes 11,000 robot lawnmowers that could be hacked and controlled worldwide

Risky robots: German researcher exposes 11,000 robot lawnmowers that could be hacked and controlled worldwide

A German security researcher has exposed a serious set of vulnerabilities in Yarbo’s internet-connected robot lawnmowers, showing that the machines could be remotely accessed and controlled from anywhere in the world. In a live demonstration reported by The Verge, Andreas Makris was able to steer a Yarbo unit from nearly 6,000 miles away, with the reporter even lying in the mower’s path to show how dangerous the flaw could be. The investigation said the problem affected more than 11,000 devices globally and raised alarms not just about privacy, but about physical safety, because the robots carry spinning blades and can operate autonomously in people’s yards.

How hackers could remotely control thousands of robot lawnmowers

Makris’ findings centred on a cluster of weaknesses in Yarbo’s remote diagnostic, credential management, and data-handling systems. The researcher found that the robots shared the same hardcoded root password, while the firmware also included a backdoor that could be used for remote access. Reports said the devices could be made to spin up their blades, probe a home network, and potentially be folded into a botnet. The risk was not limited to digital access. Makris could reportedly pull owners’ email addresses, Wi-Fi passwords, and the exact GPS coordinates of their homes from the system, while also accessing camera feeds. That meant a compromised mower could become both a surveillance device and a physical hazard. A live demonstration showed a remotely controlled robot moving towards a reporter, underscoring how an ordinary yard machine could become dangerous if the security flaws were exploited.

The scale of the exposure

Makris was reportedly tracking more than 11,000 Yarbo devices worldwide, with around 5,400 mapped across the United States and Europe at the time of the demonstration. Reports also noted that the company sells modular yard robots capable of operating as a lawn mower, leaf blower, snowblower, trimmer, or edger, all powered by the same core machine. That architecture meant the vulnerabilities could potentially affect multiple products across Yarbo’s lineup.

The CVEs explain the technical risks

The disclosure was backed by multiple officially tracked security vulnerabilities. According to the US National Vulnerability Database, one flaw involved a hidden backdoor inside Yarbo’s firmware that could allow remote access to the robot without proper authentication. Researchers said the backdoor could not be disabled through normal user settings and would remain active even after factory resets or software updates.Another vulnerability involved the mower’s MQTT communication system, which reportedly allowed anonymous connections without proper security restrictions. In simple terms, someone on the same network could potentially intercept sensitive data or send commands directly to the robot.A separate security advisory also revealed that Yarbo devices reportedly used the same built-in administrator username and password across all machines. Researchers said users could not permanently change or remove these credentials, meaning anyone who discovered them could potentially gain deep access to the mower’s internal systems and remote management controls.

How Yarbo responded

Yarbo later acknowledged the problem in an official update and said the core technical findings were accurate. The company said it had temporarily cut off remote access and was working on remediation, including stronger access controls, improved authentication, greater user visibility over remote diagnostic features, and the reduction of unnecessary legacy support mechanisms. The Verge’s follow-up report said Yarbo had also apologised and created a dedicated security response centre.

What users of connected devices should take from this

The incident shows why owners should be cautious about devices that depend on cloud access and remote diagnostics. For robot lawnmowers and other IoT products, the safest approach is to keep firmware updated, review remote-access settings, isolate devices on separate home networks where possible, and pay attention to vendor security disclosures. In Yarbo’s case, the official response suggests that some remediation is underway, but the disclosure itself shows how quickly convenience can turn into exposure when security is bolted on too late. Go to Source

Hot this week

‘Bought The TV For Her Face’: Dua Lipa Sues Samsung For $15M For Using Her Face On TV Box

The pop star alleges Samsung used her image on millions of TV boxes “without her knowledge” and remained “callous” when asked to stop. Read More

‘Play Tamil song before Vande Mataram’: Row over national song at TVK chief Vijay’s swearing in escalates

M Veerapandiyan and Vijay NEW DELHI: CPI state secretary M Veerapandiyan on Sunday said that the ‘Tamil Thaai Vaazhthu’ (state song of Tamil Nadu) must be accorded the foremost place in the protocol of government ceremon Read More

Gelatin sticks found along PM Modi’s route near Vaderahalli hours before his convoy passed

BENGALURU: A major security alert was triggered hours before Prime Minister Narendra Modi’s visit to the Art of Living on Sunday. Read More

How Bengal Police Came Under Political Control & Challenges Ahead Of New Suvendu Adhikari Govt

Police experts and retired officers believe dismantling this entrenched system will be one of the biggest challenges before the new government led by Suvendu Adhikari Go to Source Read More

Topics

‘Bought The TV For Her Face’: Dua Lipa Sues Samsung For $15M For Using Her Face On TV Box

The pop star alleges Samsung used her image on millions of TV boxes “without her knowledge” and remained “callous” when asked to stop. Read More

‘Play Tamil song before Vande Mataram’: Row over national song at TVK chief Vijay’s swearing in escalates

M Veerapandiyan and Vijay NEW DELHI: CPI state secretary M Veerapandiyan on Sunday said that the ‘Tamil Thaai Vaazhthu’ (state song of Tamil Nadu) must be accorded the foremost place in the protocol of government ceremon Read More

Gelatin sticks found along PM Modi’s route near Vaderahalli hours before his convoy passed

BENGALURU: A major security alert was triggered hours before Prime Minister Narendra Modi’s visit to the Art of Living on Sunday. Read More

How Bengal Police Came Under Political Control & Challenges Ahead Of New Suvendu Adhikari Govt

Police experts and retired officers believe dismantling this entrenched system will be one of the biggest challenges before the new government led by Suvendu Adhikari Go to Source Read More

London Sikh restaurateur to sue Met police and mayor Sadiq Khan over ‘continuous discriminatory treatment’ amid non-halal row

London-based restaurateur Harman Singh Kapoor has announced plans to take legal action against the Metropolitan Police and London Mayor Sadiq Khan after being released from custody following his arrest linked to ongoing tensions surro Read More

Hantavirus outbreak: Cruise ship passengers start disembarking in Spain, all to be checked for symptoms

Passengers are disembarked from the hantavirus-stricken cruise ship MV Hondius (AP photo) As the outbreak of hantavirus aboard a cruise ship triggered international concern, passengers on the quarantined vessel began disembarking on Read More

Spain begins evacuation of hantavirus-hit cruise ship off Tenerife coast

Spain has begun evacuating passengers and crew from the virus-hit cruise ship MS Hondius, which is anchored off the coast of Tenerife in the Canary Islands after a hantavirus outbreak on board. Read More

Related Articles