CVE-2025-29659

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:yiiot:xy-3820_firmware:6.0.24.10:*:*:*:*:*:*:*
cpe:2.3:h:yiiot:xy-3820:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-21 15:16

Updated : 2025-06-23 13:42


NVD link : CVE-2025-29659

Mitre link : CVE-2025-29659

CVE.ORG link : CVE-2025-29659


JSON object : View

Products Affected

yiiot

  • xy-3820
  • xy-3820_firmware
CWE
CWE-285

Improper Authorization