#VU15685 OS command injection in Yi Home Camera - CVE-2018-3890

 

#VU15685 OS command injection in Yi Home Camera - CVE-2018-3890

Published: November 2, 2018


Vulnerability identifier: #VU15685
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-3890
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Yi Home Camera
Software vendor:
YI Technology

Description

The vulnerability allows a physical attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to a logic flaw during insufficient sanitization of user-supplied data. A physical attacker can insert an SD card to inject arbitrary OS commands and execute arbitrary code with elevated privileges. 

Successful exploitation of the vulnerability may result in system compromise.


Remediation

Update to the latest version.

External links