Vulnerability Description
A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wyze | Cam V4 Firmware | <= 4.52.4.9887 |
| Wyze | Cam V4 | All versions |
Related Weaknesses (CWE)
References
- https://forums.wyze.com/t/security-advisory/289256Vendor Advisory
- https://hiddenlayer.com/sai-security-advisory/2024-7-wyze/ExploitThird Party Advisory
- https://forums.wyze.com/t/security-advisory/289256Vendor Advisory
- https://hiddenlayer.com/sai-security-advisory/2024-7-wyze/ExploitThird Party Advisory
FAQ
What is CVE-2024-37066?
CVE-2024-37066 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup proces...
How severe is CVE-2024-37066?
CVE-2024-37066 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-37066?
Check the references section above for vendor advisories and patch information. Affected products include: Wyze Cam V4 Firmware, Wyze Cam V4.