VORANT. Threat Intelligence Sign in Get the full feed

AL-KO Robolinho lawn mower update software contains hard-coded AWS credentials…

high vulnerability manufacturing

AL-KO Robolinho lawn mower update software contains hard-coded AWS credentials (CVE-2026-1612) allowing unauthorized access to vendor's cloud storage.

CERT Polska coordinated disclosure of CVE-2026-1612, a critical vulnerability in AL-KO Robolinho Update Software version 8.0.21.0610. The application contains hard-coded AWS Access and Secret keys that provide at least read access to AL-KO's AWS S3 bucket. Direct use of these credentials may grant attackers broader permissions than intended by the application design. The exposure of cloud credentials represents a supply chain risk, as attackers could potentially access firmware updates, customer data, or other sensitive resources stored in the vendor's infrastructure.

The vendor was notified early in the disclosure process but failed to respond to CERT Polska's communications. While only version 8.0.21.0610 was confirmed vulnerable through testing, other versions may also contain the same hard-coded credentials. The vulnerability was responsibly reported by security researcher Piotr Ptaszek. Organizations using AL-KO Robolinho robotic lawn mowers should monitor for vendor updates and consider network segmentation to limit exposure of IoT devices until a patch is available.

Mentioned in this report

Vulnerabilities CVE-2026-1612

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1612

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free