Critical severity9.8NVD Advisory· Published Apr 21, 2025· Updated Jun 17, 2026
CVE-2025-29660
CVE-2025-29660
Description
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traversal techniques.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:yiiot:xy-3820_firmware:6.0.24.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-29660nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.