OS command injection in Yi Home Camera - CVE-2018-3890

 

OS command injection in Yi Home Camera - CVE-2018-3890

Published: November 2, 2018


Vulnerability identifier: #VU15685
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-3890
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: YI Technology
Affected software:
Yi Home Camera

Detailed vulnerability description

The vulnerability allows a physical attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to a logic flaw during insufficient sanitization of user-supplied data. A physical attacker can insert an SD card to inject arbitrary OS commands and execute arbitrary code with elevated privileges. 

Successful exploitation of the vulnerability may result in system compromise.


How to mitigate CVE-2018-3890

Update to the latest version.

Sources