CVE-2024-37066: Wyze Cam v4 Firmware

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during the camera setup process.

Affected products

  • Wyze Cam v4 Firmware: up to and including 4.52.4.9887

Published 2024-07-19. Last modified 2026-06-17.