Vulnerability Details CVE-2018-3890
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution. An attacker can insert an SD card to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.3%
CVSS Severity
CVSS v3 Score 7.6
CVSS v2 Score 4.6
Products affected by CVE-2018-3890
-
cpe:2.3:h:yitechnology:yi_home_camera:-
-
cpe:2.3:o:yitechnology:yi_home_camera_firmware:1.8.7.0d