CVE-2024-37066
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.
Affected (1)
Products: Wyze: Cam V4 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.52.4.9887 |
| Running on/with | Platform Versions |
|---|---|
Wyze Cam V4 | All versions |
References (4)
Source: 6f8de1f0-f67e-45a6-b68f-98777fdb759c
Vendor Advisory
Source: 6f8de1f0-f67e-45a6-b68f-98777fdb759c
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.