VulnerabilityModified
CVE-2024-37066
A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.
HIGH 8.8EPSS 1.84%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- wyze/cam v4 firmware
- Source
- 6f8de1f0-f67e-45a6-b68f-98777fdb759c
References
- https://forums.wyze.com/t/security-advisory/289256Vendor Advisory
- https://hiddenlayer.com/sai-security-advisory/2024-7-wyze/Exploit, Third Party Advisory
- https://forums.wyze.com/t/security-advisory/289256Vendor Advisory
- https://hiddenlayer.com/sai-security-advisory/2024-7-wyze/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.