Code Execution Vulnerability in Yi Home Camera by Yi Technology
CVE-2018-3920
What is CVE-2018-3920?
A vulnerability exists in the firmware update functionality of the Yi Home Camera, specifically in version 27US 1.8.7.0D. This flaw can be exploited via a specially crafted 7-Zip file which can trigger a CRC collision. When the camera processes this manipulated file, it may initiate a firmware update allowing unauthorized code execution. An attacker could exploit this by inserting an SD card containing the malicious 7-Zip file, thereby gaining access to the device's firmware and potentially executing arbitrary code.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Yi Technology Yi Technology Home Camera 27US 1.8.7.0D
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
