Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.
                
            References
                    | Link | Resource | 
|---|---|
| https://geochen.medium.com/cve-2024-56897-yi-car-dashcam-39304a4b21b4 | Exploit Third Party Advisory | 
| https://github.com/geo-chen/YI-Smart-Dashcam/ | Exploit Third Party Advisory | 
| https://yitechnology.com.sg/products/dash-camera/ | Broken Link | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    03 Mar 2025, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
| References | () https://geochen.medium.com/cve-2024-56897-yi-car-dashcam-39304a4b21b4 - Exploit, Third Party Advisory | |
| References | () https://github.com/geo-chen/YI-Smart-Dashcam/ - Exploit, Third Party Advisory | |
| References | () https://yitechnology.com.sg/products/dash-camera/ - Broken Link | |
| First Time | Yitechnology yi Car Dashcam Yitechnology yi Car Dashcam Firmware Yitechnology | |
| CWE | CWE-434 | |
| CPE | cpe:2.3:h:yitechnology:yi_car_dashcam:-:*:*:*:*:*:*:* cpe:2.3:o:yitechnology:yi_car_dashcam_firmware:3.88:*:*:*:*:*:*:* | |
| Summary | 
 | 
24 Feb 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-02-24 16:15
Updated : 2025-03-03 20:15
NVD link : CVE-2024-56897
Mitre link : CVE-2024-56897
CVE.ORG link : CVE-2024-56897
JSON object : View
Products Affected
                yitechnology
- yi_car_dashcam
- yi_car_dashcam_firmware
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
