CVE-2025-29659

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:yiiot:xy-3820_firmware:6.0.24.10:*:*:*:*:*:*:*
cpe:2.3:h:yiiot:xy-3820:-:*:*:*:*:*:*:*

History

23 Jun 2025, 13:42

Type Values Removed Values Added
CPE cpe:2.3:h:yiiot:xy-3820:-:*:*:*:*:*:*:*
cpe:2.3:o:yiiot:xy-3820_firmware:6.0.24.10:*:*:*:*:*:*:*
First Time Yiiot
Yiiot xy-3820
Yiiot xy-3820 Firmware
References () https://github.com/Yasha-ops/RCE-YiIOT - () https://github.com/Yasha-ops/RCE-YiIOT - Exploit, Vendor Advisory
References () https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-29659 - () https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-29659 - Exploit, Third Party Advisory

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) Yi IOT XY-3820 6.0.24.10 es vulnerable a la ejecución remota de comandos a través de la función "cmd_listen" ubicada en el binario "cmd".

21 Apr 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-21 15:16

Updated : 2025-06-23 13:42


NVD link : CVE-2025-29659

Mitre link : CVE-2025-29659

CVE.ORG link : CVE-2025-29659


JSON object : View

Products Affected

yiiot

  • xy-3820_firmware
  • xy-3820
CWE
CWE-285

Improper Authorization