CVE-2026-4478 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: March 20, 2026
Yi Technology YI Home Camera 2 - Authentication Bypass
Published: March 20, 2026Updated: March 20, 2026Remote Exploitable
Overview
Yi Technology YI Home Camera 2 2.1.1_20171024151200 contains a broken authentication caused by improper verification of cryptographic signature in HTTP Firmware Update Handler, letting remote attackers bypass authentication, exploit requires high attack complexity.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Remote attackers can bypass authentication, potentially leading to unauthorized access or control of the device.
Mitigation
Update to the latest firmware version provided by the vendor.
References
Related Resources
Details
- CVE ID
- CVE-2026-4478
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_authentication
- Status
- new
CWE
- CWE-345
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H