PT-2025-17441 · Yi · Yi Iot Xy-3820
Yasha-Ops
·
Published
2025-04-21
·
Updated
2025-06-23
·
CVE-2025-29660
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Yi IOT XY-3820 version 6.0.24.10
Description
A vulnerability exists in the daemon process of the Yi IOT XY-3820, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traversal techniques.
Recommendations
For version 6.0.24.10, as a temporary workaround, consider restricting access to the TCP service on port 6789 until a patch is available. Avoid using directory traversal techniques in TCP requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yi Iot Xy-3820