# AL-KO Robolinho lawn mower update software contains hard-coded AWS credentials…

Published: 2026-03-30 · Severity: high · Sectors: manufacturing
Canonical: https://vorant.io/reports/19665e53-0723-47cc-9906-afe25d8432d9/al-ko-robolinho-lawn-mower-update-software-contains-hard-coded-aws-credentials

> AL-KO Robolinho lawn mower update software contains hard-coded AWS credentials (CVE-2026-1612) allowing unauthorized access to vendor's cloud storage.

CERT Polska coordinated disclosure of CVE-2026-1612, a critical vulnerability in AL-KO Robolinho Update Software version 8.0.21.0610. The application contains hard-coded AWS Access and Secret keys that provide at least read access to AL-KO's AWS S3 bucket. Direct use of these credentials may grant attackers broader permissions than intended by the application design. The exposure of cloud credentials represents a supply chain risk, as attackers could potentially access firmware updates, customer data, or other sensitive resources stored in the vendor's infrastructure.

The vendor was notified early in the disclosure process but failed to respond to CERT Polska's communications. While only version 8.0.21.0610 was confirmed vulnerable through testing, other versions may also contain the same hard-coded credentials. The vulnerability was responsibly reported by security researcher Piotr Ptaszek. Organizations using AL-KO Robolinho robotic lawn mowers should monitor for vendor updates and consider network segmentation to limit exposure of IoT devices until a patch is available.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1612

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1612

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/19665e53-0723-47cc-9906-afe25d8432d9/al-ko-robolinho-lawn-mower-update-software-contains-hard-coded-aws-credentials.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
