CVE-2026-4475

8.8

Yi Technology · YI Home Camera 2

A hard-coded credential vulnerability in the Yi Technology YI Home Camera 2 allows unauthorized access to devices on the local network.

Executive summary

The YI Home Camera 2 contains hard-coded credentials that grant an attacker full control over the device if they have access to the local network.

Vulnerability

This vulnerability involves the use of hard-coded credentials within the web interface of the camera (home/web/ipc). The flaw is reachable by unauthenticated attackers who maintain access to the local network where the device resides.

Business impact

Successful exploitation of this vulnerability results in full administrative control over the affected camera, leading to a total loss of confidentiality, integrity, and availability. With a CVSS score of 8.8, this represents a high-severity risk that could lead to unauthorized surveillance, data exfiltration, or the integration of the device into a botnet.

Remediation

Immediate Action: As the vendor has not provided an official patch, administrators should isolate affected cameras from the local network using VLANs or firewall rules to prevent unauthorized access.

Proactive Monitoring: Monitor network traffic for unusual authentication attempts or connections originating from the camera management interface.

Compensating Controls: Deploy a network-level intrusion detection system or firewall policy to restrict access to the camera's management port to authorized management hosts only.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as disclosed in the VulDB reference (ID 351765).

Analyst recommendation

Given the high CVSS score and the presence of a public proof-of-concept, this vulnerability poses a significant risk to organizational security. Because the vendor has not responded to disclosure, users are strongly advised to isolate these devices from critical networks immediately to prevent potential compromise.

Sources

Originally found and disclosed by 0rbitingZer0 (VulDB User), with VulDB (coordinator), per the CVE Program record.