Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.
References
| Link | Resource |
|---|---|
| https://geochen.medium.com/cve-2024-56897-yi-car-dashcam-39304a4b21b4 | Exploit Third Party Advisory |
| https://github.com/geo-chen/YI-Smart-Dashcam/ | Exploit Third Party Advisory |
| https://yitechnology.com.sg/products/dash-camera/ | Broken Link |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-02-24 16:15
Updated : 2025-03-03 20:15
NVD link : CVE-2024-56897
Mitre link : CVE-2024-56897
CVE.ORG link : CVE-2024-56897
JSON object : View
Products Affected
yitechnology
- yi_car_dashcam_firmware
- yi_car_dashcam
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
