CVE-2025-29660

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 21, 2025
Updated: Apr 23, 2025
CWE ID 22

Summary

CVE-2025-29660 is a vulnerability affecting the daemon process of the Yi IOT XY-3820 v6.0.24.10. A TCP service, reachable on port 6789, is the source of the issue. The service is susceptible to input validation flaws, which can be exploited by attackers to execute arbitrary scripts residing on the device. This can be accomplished through the utilization of directory traversal techniques in specially crafted TCP requests.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share