Lucene search

K
zdiRafal GorylZDI-24-839
HistoryJun 21, 2024 - 12:00 a.m.

(Pwn2Own) Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability

2024-06-2100:00:00
Rafal Goryl
www.zerodayinitiative.com
wyze cam v3
cloud infrastructure
authentication
vulnerability
remote code execution

7.2 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to exploit this vulnerability. The specific flaw exists within the run_action_batch endpoint of the cloud infrastructure. The issue results from the use of the device’s MAC address as a sole credential for authentication. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.

7.2 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%