CVE-2018-3891 describes a firmware downgrade vulnerability in Yi Home Camera 27US 1.8.7.0D, allowing an attacker to force an older, potentially less secure firmware version onto the device. With a CVSS score of 4.6 (Medium), this vulnerability requires physical access to insert a specially crafted SD card, but no user interaction is needed. Successful exploitation could lead to a loss of integrity by downgrading the firmware, though confidentiality and availability are not directly impacted. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.7.0dCPE matchmatch criteria | cpe:2.3:o:yitechnology:yi_home_camera_firmware:1.8.7.0d:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.