PT-2025-17440 · Yi · Yi Iot Xy-3820

Yassine Damiri

·

Published

2025-04-21

·

Updated

2025-06-23

·

CVE-2025-29659

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yi IOT XY-3820 version 6.0.24.10
Description The issue concerns Remote Command Execution via the cmd listen function located in the cmd binary.
Recommendations For Yi IOT XY-3820 version 6.0.24.10, as a temporary workaround, consider disabling the cmd listen function until a patch is available. Restrict access to the cmd binary to minimize the risk of exploitation.

Exploit

Fix

RCE

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-29659

Affected Products

Yi Iot Xy-3820