CVE-2024-56897: Malicious File Upload
Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56897?
The severity of CVE-2024-56897 is high due to improper access control allowing unauthorized actions on the YI Car Dashcam.
How do I fix CVE-2024-56897?
To fix CVE-2024-56897, it is recommended to update the YI Car Dashcam to the latest firmware version that addresses this vulnerability.
What are the risks associated with CVE-2024-56897?
The risks associated with CVE-2024-56897 include unauthorized file downloads, uploads, and modifications to device settings.
Which versions of YI Car Dashcam are affected by CVE-2024-56897?
CVE-2024-56897 specifically affects YI Car Dashcam firmware version 3.88.
What type of access does CVE-2024-56897 exploit?
CVE-2024-56897 exploits improper access control in the HTTP server to allow unrestricted access to API commands.