#VU16712 Improper input validation in Yi Home Camera - CVE-2018-3920
Published: December 26, 2018
Yi Home Camera
YI Technology
Description
The vulnerability exists due to an error in the firmware update functionality during insufficient sanitization of user-supplied data. A physical attacker can insert an SDcard containing 7-Zip file, trigger a CRC collision and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.