CVE-2018-20007
16.05.2019, 19:29
Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shell. The attacker can then exfiltrate the audio data, read cleartext Wi-Fi credentials in a log file, or access other sensitive device and user information.Enginsight
Vendor | Product | Version |
---|---|---|
yeelight | smart_ai_speaker_firmware | 3.3.10_0074:_0074 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration