PT-2024-27282 · Wyze · Wyze V4 Pro

Published

2024-07-19

·

Updated

2024-08-22

·

CVE-2024-37066

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wyze V4 Pro firmware versions prior to 4.50.4.9222
Description A command injection issue exists, allowing attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.
Recommendations For Wyze V4 Pro firmware versions prior to 4.50.4.9222, update to version 4.50.4.9222 or later to resolve the issue.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-37066

Affected Products

Wyze V4 Pro