Yitechnology develops a focused product line of smart home cameras and automotive dashcams, along with their associated firmware components, that are moderately prominent in the consumer IoT and vehicle-telematics landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including buffer overflows, sensitive information exposure, OS command injection, and memory-boundary violations that are characteristic of embedded camera firmware. Defenders should prioritize inventory and patching of affected camera models and firmware versions, particularly in networked and vehicle-mounted deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yitechnology over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3934CRITICAL An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic fl | Nov 2, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-3900HIGH An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, r | Nov 1, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-3892HIGH An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, re | Nov 2, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-3947HIGH An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sniff network traffic to exploit t | Nov 1, 2018 | 8.1 | 26 | NO | NO |
CVE-2018-3910HIGH An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, res | Nov 1, 2018 | 8.0 | 26 | NO | NO |
CVE-2018-3935HIGH An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can allocate unlimited m | Nov 2, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-3899HIGH An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, r | Nov 2, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-3898HIGH An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, r | Nov 2, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-3928HIGH An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings | Nov 1, 2018 | 7.5 | 25 | NO | NO |
CVE-2024-56897CRITICAL Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized | Feb 24, 2025 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yitechnology.
Media articles that mention a CVE ID that affects a product developed by Yitechnology — matched by CVE ID, not by vendor name.