#VU15694 Authorization bypass in Yi Home Camera - CVE-2018-3934
Published: November 2, 2018
Yi Home Camera
YI Technology
Description
The vulnerability exists due to a logic flaw in the firmware update functionality during insufficient sanitization of user-supplied data. A remote attacker can sniff network traffic and send a set of UDP packets to bypass authentication and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.