216.73.216.226

CVE-2026-4478

· Published 20/03/2026 07:16 · Modified 20/03/2026 13:37

Labels: CVE-2026-4478 2026-03-20CVE-2026-4478CWE-345[email protected]

Essential information

Published
20/03/2026 07:16
Modified
20/03/2026 13:37
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of the component HTTP Firmware Update Handler. The manipulation leads to improper verification of cryptographic signature. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
yi technology / yi home camera cpe:2.3:a:yi_technology:yi_home_camera:2.1.1_20171024151200:*:*:*:*:*:*:*

References