Beveiligingsadvies

CVE-2024-56897

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-24 00:00:00
Laatst bijgewerkt 2025-03-03 19:40:36
Toegewezen door mitre
CVSS-score 9.8
Status PUBLISHED

Beschrijving

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.