PT-2025-7770 · Yi · Yi Car Dashcam
Geo-Chen
·
Published
2025-02-24
·
Updated
2025-03-03
·
CVE-2024-56897
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YI Car Dashcam version 3.88
Description
The issue is related to improper access control in the HTTP server, allowing unauthorized actions such as unrestricted file downloads and uploads. Additionally, API commands can be made to modify device settings without proper authorization, including disabling recording, disabling sounds, and performing a factory reset.
Recommendations
For YI Car Dashcam version 3.88, consider restricting access to the HTTP server and API commands until a patch is available. As a temporary workaround, avoid using the device's API for sensitive operations and limit access to the device's settings to prevent unauthorized modifications.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yi Car Dashcam