← Back

CVE-2025-29660

nvd nist
Published: Apr 21, 2025Modified: Jun 23, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traversal techniques.

Affected (1)

1 product
Xy 3820 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.0.24.10
Running on/withPlatform Versions
Yiiot
Xy 3820
All versions

References (2)

Source: cve@mitre.org
ExploitVendor Advisory

Timeline

No history available yet.