CVE-2026-4475 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: March 20, 2026
Yi Technology YI Home Camera 2 - Hardcoded Credentials
Published: March 20, 2026Updated: March 20, 2026
Overview
Yi Technology YI Home Camera 2 2.1.1_20171024151200 contains a hardcoded credentials vulnerability caused by manipulation of an unknown function in home/web/ipc, letting attackers with local network access gain unauthorized access.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Attackers on the local network can gain unauthorized access using hardcoded credentials, compromising device security.
Mitigation
Update to the latest available version or contact vendor for a patch.
References
Related Resources
Details
- CVE ID
- CVE-2026-4475
- Severity
- High
- CVSS Score
- 8.8
- Type
- hardcoded_credentials
- Status
- new
CWE
- CWE-259
CVSS Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H