PT-2025-7770 · Yi · Yi Car Dashcam

Geo-Chen

·

Published

2025-02-24

·

Updated

2025-03-03

·

CVE-2024-56897

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YI Car Dashcam version 3.88
Description The issue is related to improper access control in the HTTP server, allowing unauthorized actions such as unrestricted file downloads and uploads. Additionally, API commands can be made to modify device settings without proper authorization, including disabling recording, disabling sounds, and performing a factory reset.
Recommendations For YI Car Dashcam version 3.88, consider restricting access to the HTTP server and API commands until a patch is available. As a temporary workaround, avoid using the device's API for sensitive operations and limit access to the device's settings to prevent unauthorized modifications.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56897

Affected Products

Yi Car Dashcam