# CVE-2026-4475

## Summary

- **CVE ID:** CVE-2026-4475
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-798, CWE-259
- **Published:** Mar 20, 2026
- **Last Modified:** Mar 20, 2026

## Description

A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation leads to hard-coded credentials. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected Products

- Yi Technology — YI Home Camera (2 2.1.1_20171024151200)

## References

- [CNA](https://vuldb.com/?id.351765)
- [CNA](https://vuldb.com/?ctiid.351765)
- [CNA](https://vuldb.com/?submit.772996)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._