Hard-coded AWS Keys Found in AL-KO Robolinho App
AL-KO Robolinho Update Software embeds hard-coded AWS keys that let anyone read objects in AL-KO's S3 bucket, with the vendor unresponsive to disclosure.
CERT Polska coordinated disclosure of CVE-2026-1612, a vulnerability affecting AL-KO Robolinho Update Software in which hard-coded AWS Access and Secret keys are embedded in the application. These credentials grant at least read access to some objects in AL-KO's AWS S3 bucket, and could potentially allow greater access than intended by the application itself if abused directly rather than through the app.
Only version 8.0.21.0610 has been confirmed vulnerable, though other versions may also be affected since they were not tested. The vendor was notified early in the disclosure process but did not respond, leaving the issue unmitigated at time of publication. This is a supply-chain/credential-exposure issue typical of hard-coded secrets in IoT/embedded update mechanisms, posing a risk of unauthorized data access rather than remote code execution.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1612
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free