LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4478 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 20, 2026

Yi Technology YI Home Camera 2 - Authentication Bypass

Published: March 20, 2026Updated: March 20, 2026Remote Exploitable

Overview

Yi Technology YI Home Camera 2 2.1.1_20171024151200 contains a broken authentication caused by improper verification of cryptographic signature in HTTP Firmware Update Handler, letting remote attackers bypass authentication, exploit requires high attack complexity.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Remote attackers can bypass authentication, potentially leading to unauthorized access or control of the device.

Mitigation

Update to the latest firmware version provided by the vendor.

Details

CVE ID
CVE-2026-4478
Severity
High
CVSS Score
8.1
Type
broken_authentication
Status
new

CWE

  • CWE-345

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H