Vulnerabilities > Yeelight > Smart AI Speaker Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-05-16 CVE-2018-20007 Incorrect Permission Assignment for Critical Resource vulnerability in Yeelight Smart AI Speaker Firmware 3.3.100074
Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shell.
local
low complexity
yeelight CWE-732
7.2