CVE-2026-4478Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of the component HTTP Firmware Update Handler. The manipulation leads to improper verification of cryptographic signature. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-20: 3Technical Details · 2026-03-20: 203-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4478 - High A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of the component HTTP Firmware Update Handler. ... https://www.thehackerwire.com/vulnerability/CVE-2026-4478/ https://t.co/kefnJXKveE

    Post summary

    The post announces CVE-2026-4478 as a high‑severity vulnerability affecting Yi Technology YI Home Camera 2's firmware update handler, pointing readers to a Hacker Wire article for more details.

    0000040
    138 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4478 - Yi Technology - YI Home Camera - https://www.redpacketsecurity.com/cve-alert-cve-2026-4478-yi-technology-yi-home-camera/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4478 #yi-technology #yi-home-camera

    Post summary

    The announcement merely references CVE-2026-4478 for Yi Technology's YI Home Camera and provides a link to an alert page, without any detailed technical or exploit information.

    0000074
    3.6K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4478: Yi Technology YI Home Camera HTTP... Broken signature verification in YI Home Camera firmware updates = remote code execution with a crafted payload - IoT bo... https://zerodaysignal.com/vulnerability/CVE-2026-4478 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a newly disclosed vulnerability (CVE-2026-4478) in YI Home Camera firmware, detailing broken signature verification that allows remote code execution via crafted payloads.

    0000075
    155 followersView on X

Explore more