CVE-2025-29659: Critical severity yi iot xy-3820 vulnerability
Published Apr 21, 2025
·Updated
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmdlisten" function located in the "cmd" binary.
Affected Software
3 affected components
Yi IOT XY-3820
All of the following
Yiiot Xy-3820 Firmware=6.0.24.10
Yiiot Xy-3820
Event History
Apr 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29659?
CVE-2025-29659 is considered to be a high severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2025-29659?
To mitigate CVE-2025-29659, it is recommended to update the Yi IOT XY-3820 device firmware to the latest version provided by the vendor.
3
What systems are affected by CVE-2025-29659?
CVE-2025-29659 specifically affects the Yi IOT XY-3820 device running version 6.0.24.10.
4
What type of vulnerability is CVE-2025-29659?
CVE-2025-29659 is a remote command execution vulnerability that can be exploited by attackers to execute arbitrary commands on the affected device.
5
Can CVE-2025-29659 be exploited remotely?
Yes, CVE-2025-29659 allows attackers to exploit the vulnerability remotely without physical access to the device.