Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wyze

First CVE: Mar 30, 2022Active for: 4 yearsTotal CVEs: 10
36.0
VTI Score
Medium

Wyze manufactures a modestly represented line of consumer security cameras and related IoT devices that have drawn vulnerability attention despite their narrow product scope, positioning them among more prominent vendors in the embedded-camera space. Vulnerabilities affecting this vendor skew toward serious outcomes, particularly through memory-safety issues such as out-of-bounds writes, buffer overflows (both stack and heap-based), alongside authentication and command-injection flaws that are characteristic of firmware-based embedded systems with limited memory and input-validation constraints. Defenders should prioritize patching and network isolation for Wyze camera deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wyze over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2022
4 years ago
Most Recent CVE
Nov 22, 2024
609 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12266CRITICAL
Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 ve
Mar 30, 20229.831NONO
CVE-2024-6246HIGH
Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on a
Nov 22, 20248.827NONO
CVE-2019-9564CRITICAL
A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versi
Mar 30, 20229.827NONO
CVE-2024-37066HIGH
A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the
Jul 19, 20248.826NONO
CVE-2023-6324HIGH
ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
May 15, 20248.826NONO
CVE-2023-6322HIGH
A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A spec
May 15, 20248.825NONO
CVE-2024-6249HIGH
Wyze Cam v3 TCP Traffic Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on
Nov 22, 20248.824NONO
CVE-2024-6248HIGH
Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affe
Nov 22, 20247.521NONO
CVE-2024-6247MEDIUM
Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected instal
Nov 22, 20246.820NONO
CVE-2023-6323MEDIUM
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
May 15, 20246.520NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
20%
60%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (40.0%)
Unknown0 (0.0%)
Physical1 (10.0%)
Adjacent Network5 (50.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wyze.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wyze — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wyze's Products

View all 3 CNAs →

Top CWEs