#VU15685 OS command injection in Yi Home Camera - CVE-2018-3890
Published: November 2, 2018
Vulnerability identifier: #VU15685
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-3890
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Yi Home Camera
Yi Home Camera
Software vendor:
YI Technology
YI Technology
Description
The vulnerability allows a physical attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to a logic flaw during insufficient sanitization of user-supplied data. A physical attacker can insert an SD card to inject arbitrary OS commands and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Remediation
Update to the latest version.