CVE-2018-3920

CVE-2018-3920

An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability.

Source: CVE-2018-3920

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다