Back to search
CVE-2018-20007
Published: May 16, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shell. The attacker can then exfiltrate the audio data, read cleartext Wi-Fi credentials in a log file, or access other sensitive device and user information.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://forum.yeelight.com/
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now