#VU15692 OS command injection in Yi Home Camera - CVE-2018-3910
Published: November 2, 2018
Yi Home Camera
YI Technology
Description
The vulnerability exists due to a flaw in in the cloud OTA setup functionality during insufficient sanitization of user-supplied data. An adjacent attacker can trick the victim into connecting their camera to this SSID to inject arbitrary OS commands and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.