CVE-2018-3890: Command Injection
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution. An attacker can insert an SD card to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3890?
CVE-2018-3890 has a high severity rating due to its potential for code execution via a logic flaw and command injection.
How do I fix CVE-2018-3890?
To fix CVE-2018-3890, users should update the Yi Home Camera firmware to the latest version released by Yitechnology.
What type of attacks can exploit CVE-2018-3890?
CVE-2018-3890 can be exploited through specially crafted firmware update files inserted via an SD card.
Which devices are affected by CVE-2018-3890?
CVE-2018-3890 specifically affects the Yi Home Camera running firmware version 1.8.7.0D.
Is there a workaround for CVE-2018-3890?
Currently, the best mitigation for CVE-2018-3890 is to refrain from using SD cards for firmware updates until the issue is patched.