Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.
References
Link | Resource |
---|---|
https://geochen.medium.com/cve-2024-56897-yi-car-dashcam-39304a4b21b4 | Exploit Third Party Advisory |
https://github.com/geo-chen/YI-Smart-Dashcam/ | Exploit Third Party Advisory |
https://yitechnology.com.sg/products/dash-camera/ | Broken Link |
Configurations
Configuration 1 (hide)
AND |
|
History
03 Mar 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
Summary |
|
|
CPE | cpe:2.3:h:yitechnology:yi_car_dashcam:-:*:*:*:*:*:*:* cpe:2.3:o:yitechnology:yi_car_dashcam_firmware:3.88:*:*:*:*:*:*:* |
|
CWE | CWE-434 | |
First Time |
Yitechnology yi Car Dashcam Firmware
Yitechnology Yitechnology yi Car Dashcam |
|
References | () https://geochen.medium.com/cve-2024-56897-yi-car-dashcam-39304a4b21b4 - Exploit, Third Party Advisory | |
References | () https://github.com/geo-chen/YI-Smart-Dashcam/ - Exploit, Third Party Advisory | |
References | () https://yitechnology.com.sg/products/dash-camera/ - Broken Link |
24 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-24 16:15
Updated : 2025-03-03 20:15
NVD link : CVE-2024-56897
Mitre link : CVE-2024-56897
CVE.ORG link : CVE-2024-56897
JSON object : View
Products Affected
yitechnology
- yi_car_dashcam_firmware
- yi_car_dashcam
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type