Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7969-vfgw-xwqv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability. Alternatively, an attacker can convince a user to connect their camera to this SSID.

An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability. Alternatively, an attacker can convince a user to connect their camera to this SSID.

EPSS

Процентиль: 35%
0.00143
Низкий

8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8
nvd
больше 7 лет назад

An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability. Alternatively, an attacker can convince a user to connect their camera to this SSID.

EPSS

Процентиль: 35%
0.00143
Низкий

8 High

CVSS3

Дефекты

CWE-78