Описание
A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.
Ссылки
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.52.4.9887 (включая)
Одновременно
cpe:2.3:o:wyze:cam_v4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:wyze:cam_v4:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01332
Низкий
6.8 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-78
CWE-78
Связанные уязвимости
CVSS3: 6.8
github
больше 1 года назад
A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.
EPSS
Процентиль: 80%
0.01332
Низкий
6.8 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-78
CWE-78