#VU15687 Buffer overflow in Yi Home Camera - CVE-2018-3892
Published: November 2, 2018
Yi Home Camera
YI Technology
Description
The vulnerability exists due to buffer overflow during insufficient sanitization of user-supplied data. An adjacent attacker can intercept and alter network traffic, trigger firmware downgrade in the time syncing functionality and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.