CVE-2018-20007

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/05/2019
Last modified:
03/10/2019

Description

Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shell. The attacker can then exfiltrate the audio data, read cleartext Wi-Fi credentials in a log file, or access other sensitive device and user information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:yeelight:smart_ai_speaker_firmware:3.3.10_0074:*:*:*:*:*:*:*
cpe:2.3:h:yeelight:smart_ai_speaker:-:*:*:*:*:*:*:*