Impact
A missing authentication flaw exists in the home/web/ipc CGI endpoint of the Yi Technology YI Home Camera. The flaw allows an attacker who has local network access to manipulate the endpoint without authenticating, thereby bypassing security controls. This leads to unauthorized access and potential compromise of the device, exposing confidential content or allowing further exploitation. The weakness is identified by CWE‑287 (Improper Authentication) and CWE‑306 (Missing Authentication at Restricted Function).
Affected Systems
The vulnerability affects the Yi Technology YI Home Camera running firmware version 2 2.1.1_20171024151200. The specific affected file is home/web/ipc within the CGI component; no other versions are listed.
Risk and Exploitability
The CVSS score is 5.3 indicating moderate severity. EPSS data is unavailable, and the issue is not listed in CISA’s KEV catalog. The attack vector requires access to the local network, but an exploit is publicly available, raising the likelihood of compromise for networks that expose the camera. The overall risk remains moderate to high for environments where the device is not properly isolated or protected.
OpenCVE Enrichment