CyberSec.Space Logo
Back to CVE Browser

CVE-2018-3934

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1400%
EPSS Percentile2.72th
PublishedNov 2, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger this vulnerability.

Affected Platforms (CPE)

💻
Yitechnology

Yi Home Camera Firmware

= 1.8.7.0d

References & Advisories

Related Vulnerabilities