Skip to content

geo-chen/YI-Smart-Dashcam

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 

Repository files navigation

YI Smart Dash Camera

CVE-2024–56897

Vulnerable Model

Unrestricted HTTP server for file downloads, uploads, and API commands

Once connected to a YI Car Dashcam using default/weak credentials, the http server is open for direct access without further authentication. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

image

http server with unrestricted downloads

image

scripted dump of all recordings

image

scripted change of camera settings

image

upload function open

About

CVE-2024–56897

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors