VYPR

XY-3820

by Yi IOT

CVEs (2)

  • CVE-2025-29660CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests…

  • CVE-2025-29659CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.