CVE-2024-6247
Last modified
CVE-2024-6247 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSIDs embedded in scanned QR codes. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22337.
Metrics
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wyze | Cam V3 Firmware | < 4.36.11.8391 |
References
- https://forums.wyze.com/t/security-advisory/289256Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-24-838/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6247?
How severe is CVE-2024-6247?
How do I fix CVE-2024-6247?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6241A vulnerability was found in Pear Admin Boot up to 2.0.2 and…9.8
- CVE-2024-6242A vulnerability exists in Rockwell Automation affected produ…7.3
- CVE-2024-6243The HTML Forms WordPress plugin before 1.3.33 does not sani…4.8
- CVE-2024-6244The PZ Frontend Manager WordPress plugin before 1.0.6 does n…8.8
- CVE-2024-6245Use of Default Credentials vulnerability in Maruti Suzuki Sm…7.4
- CVE-2024-6246Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow …8.8
- CVE-2024-6248Wyze Cam v3 Cloud Infrastructure Improper Authentication Rem…7.5
- CVE-2024-6249Wyze Cam v3 TCP Traffic Handling Stack-Based Buffer Overflow…8.8
- CVE-2024-6250An absolute path traversal vulnerability exists in parisneo/…7.5
- CVE-2024-6251A vulnerability, which was classified as problematic, was fo…6.1
- CVE-2024-6252A vulnerability has been found in Zorlan SkyCaiji up to 2.8 …6.1
- CVE-2024-6253A vulnerability was found in itsourcecode Online Food Orderi…9.8
Are you affected by CVE-2024-6247?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
