PT-2025-17441 · Yi · Yi Iot Xy-3820

Yasha-Ops

·

Published

2025-04-21

·

Updated

2025-06-23

·

CVE-2025-29660

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yi IOT XY-3820 version 6.0.24.10
Description A vulnerability exists in the daemon process of the Yi IOT XY-3820, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traversal techniques.
Recommendations For version 6.0.24.10, as a temporary workaround, consider restricting access to the TCP service on port 6789 until a patch is available. Avoid using directory traversal techniques in TCP requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-29660

Affected Products

Yi Iot Xy-3820