CVE-2026-4475
8.8Yi Technology · YI Home Camera 2
A hard-coded credential vulnerability in the Yi Technology YI Home Camera 2 allows unauthorized access to devices on the local network.
Executive summary
The YI Home Camera 2 contains hard-coded credentials that grant an attacker full control over the device if they have access to the local network.
Vulnerability
This vulnerability involves the use of hard-coded credentials within the web interface of the camera (home/web/ipc). The flaw is reachable by unauthenticated attackers who maintain access to the local network where the device resides.
Business impact
Successful exploitation of this vulnerability results in full administrative control over the affected camera, leading to a total loss of confidentiality, integrity, and availability. With a CVSS score of 8.8, this represents a high-severity risk that could lead to unauthorized surveillance, data exfiltration, or the integration of the device into a botnet.
Remediation
Immediate Action: As the vendor has not provided an official patch, administrators should isolate affected cameras from the local network using VLANs or firewall rules to prevent unauthorized access.
Proactive Monitoring: Monitor network traffic for unusual authentication attempts or connections originating from the camera management interface.
Compensating Controls: Deploy a network-level intrusion detection system or firewall policy to restrict access to the camera's management port to authorized management hosts only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as disclosed in the VulDB reference (ID 351765).
Analyst recommendation
Given the high CVSS score and the presence of a public proof-of-concept, this vulnerability poses a significant risk to organizational security. Because the vendor has not responded to disclosure, users are strongly advised to isolate these devices from critical networks immediately to prevent potential compromise.
Sources
Originally found and disclosed by 0rbitingZer0 (VulDB User), with VulDB (coordinator), per the CVE Program record.
- VDB-351765 | Yi Technology YI Home Camera ipc hard-coded credentials Vulnerability database entry
- VDB-351765 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #772996 | yitechnology YI Home Camera 2 2.1.1_20171024151200 Hard-coded Credentials Third-party advisory