OS command injection in Yi Home Camera - CVE-2018-3890
Published: November 2, 2018
Vulnerability identifier: #VU15685
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-3890
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: YI Technology
Affected software:
Yi Home Camera
Yi Home Camera
Detailed vulnerability description
The vulnerability allows a physical attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to a logic flaw during insufficient sanitization of user-supplied data. A physical attacker can insert an SD card to inject arbitrary OS commands and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
How to mitigate CVE-2018-3890
Update to the latest version.