CVE-2026-4478
8.1Yi Technology · YI Home Camera 2
Yi Technology YI Home Camera 2 contains an improper cryptographic signature verification flaw in its HTTP Firmware Update Handler, allowing for remote manipulation of firmware updates.
Executive summary
A critical vulnerability in the Yi Technology YI Home Camera 2 firmware allows remote attackers to bypass cryptographic signature verification, potentially leading to unauthorized firmware modification.
Vulnerability
The vulnerability resides in the HTTP Firmware Update Handler within the home/web/ipc file, where insufficient verification of cryptographic signatures occurs. This flaw allows an unauthenticated remote attacker to potentially compromise the integrity of the device firmware.
Business impact
Successful exploitation of this vulnerability could allow an attacker to upload malicious firmware to the affected camera, leading to a complete loss of device integrity and potential surveillance of the private environment. Given the CVSS score of 8.1, the risk is classified as High, as it provides an attacker the ability to maintain persistence on the device and circumvent security controls.
Remediation
Immediate Action: As there is currently no official patch available from the vendor, users should isolate affected cameras from the public internet using network segmentation or firewall rules to prevent remote access.
Proactive Monitoring: Security teams should monitor network traffic for suspicious HTTP requests directed toward the firmware update endpoints and review device logs for unauthorized configuration changes.
Compensating Controls: Deploying a Web Application Firewall or intrusion detection system configured to inspect incoming traffic for malformed firmware update payloads can help mitigate the risk of exploitation.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the technical write-up referenced by VulDB (ID 351768).
Analyst recommendation
Given the lack of a vendor-provided security update, users must prioritize isolating these devices from external network access to prevent remote exploitation. Organizations should evaluate the necessity of these devices in high-security environments and consider decommissioning them if they cannot be adequately protected through network-level controls.
Sources
Originally found and disclosed by 0rbitingZer0 (VulDB User), with VulDB (coordinator), per the CVE Program record.
- VDB-351768 | Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification Vulnerability database entry
- VDB-351768 | CTI Indicators (IOB, IOC, IOA)
- Submit #773162 | yitechnology YI Home Camera 2 2.1.1_20171024151200 HTTP Firmware OTA Without Cryptographic Signature Third-party advisory