CVE-2019-13953: Xiaoyi Yi m1 Mirrorless Camera Firmware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the camera to record or take a picture after bypassing authentication.

Affected products

  • Xiaoyi Yi m1 Mirrorless Camera Firmware: version 3.2-cn only

Published 2019-09-06. Last modified 2026-06-17.