// For flags

CVE-2018-20007

 

Severity Score

6.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shell. The attacker can then exfiltrate the audio data, read cleartext Wi-Fi credentials in a log file, or access other sensitive device and user information.

Dispositivos Yeelight Smart AI Speaker 3.3.10_0074 tienen un control de acceso incorrecto a través de la interfaz UART, lo que permite a los atacantes físicos obtener un root shell. El atacante entonces puede filtrar los datos de audio, leer credenciales de Wi-Fi en texto claro en un archivo de registro o acceder a otro dispositivo sensible e información del usuario.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-12-10 CVE Reserved
  • 2019-05-16 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Yeelight
Search vendor "Yeelight"
Smart Ai Speaker Firmware
Search vendor "Yeelight" for product "Smart Ai Speaker Firmware"
3.3.10_0074
Search vendor "Yeelight" for product "Smart Ai Speaker Firmware" and version "3.3.10_0074"
-
Affected
in Yeelight
Search vendor "Yeelight"
Smart Ai Speaker
Search vendor "Yeelight" for product "Smart Ai Speaker"
--
Safe