Wyze manufactures a modestly represented line of consumer security cameras and related IoT devices that have drawn vulnerability attention despite their narrow product scope, positioning them among more prominent vendors in the embedded-camera space. Vulnerabilities affecting this vendor skew toward serious outcomes, particularly through memory-safety issues such as out-of-bounds writes, buffer overflows (both stack and heap-based), alongside authentication and command-injection flaws that are characteristic of firmware-based embedded systems with limited memory and input-validation constraints. Defenders should prioritize patching and network isolation for Wyze camera deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wyze over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12266CRITICAL Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 ve | Mar 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-6246HIGH Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on a | Nov 22, 2024 | 8.8 | 27 | NO | NO |
CVE-2019-9564CRITICAL A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versi | Mar 30, 2022 | 9.8 | 27 | NO | NO |
CVE-2024-37066HIGH A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the | Jul 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-6324HIGH ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity | May 15, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-6322HIGH A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A spec | May 15, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-6249HIGH Wyze Cam v3 TCP Traffic Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on | Nov 22, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-6248HIGH Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affe | Nov 22, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-6247MEDIUM Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected instal | Nov 22, 2024 | 6.8 | 20 | NO | NO |
CVE-2023-6323MEDIUM ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server. | May 15, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wyze.
Media articles that mention a CVE ID that affects a product developed by Wyze — matched by CVE ID, not by vendor name.