Impact
A flaw was identified in the WPA/WPS component of the Yi Technology YI Home Camera 2. The vulnerability is triggered by executing a manipulation that causes the device to use a hard‑coded cryptographic key. The CVE description states that this action can lead to the use of the hard‑coded key but does not explicitly describe additional effects such as data decryption or unauthorized access.
Affected Systems
The affected product is Yi Technology YI Home Camera 2, specifically firmware version 2.1.1_20171024151200. No other versions are listed as affected in the data.
Risk and Exploitability
This exploit requires local network access, entails high complexity and is reported as difficult to execute. The CVSS score is 2.3, EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The combination of local‑only attack surface, high complexity, and low severity score indicates a low to moderate overall risk, contingent on network segregation and device exposure.
OpenCVE Enrichment