CVE-2019-9564

Authentication bypass in Wyze Cam Pan v2, Cam v2 and Cam v3

Description

A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

Remediation

Solution:

  • An update to the following firmware versions fixes the issue: Wyze Cam Pan v2 firmware version 4.49.1.47. Wyze Cam v2 firmware version 4.9.8.1002. Wyze Cam v3 firmware version 4.36.8.32.

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.24%
Third-Party Advisory bitdefender.com
Affected: Wyze Cam Pan v2
Affected: Wyze Cam v2
Affected: Wyze Cam v3
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2019-9564?
CVE-2019-9564 has been scored as a high severity vulnerability.
How to fix CVE-2019-9564?
To fix CVE-2019-9564: An update to the following firmware versions fixes the issue: Wyze Cam Pan v2 firmware version 4.49.1.47. Wyze Cam v2 firmware version 4.9.8.1002. Wyze Cam v3 firmware version 4.36.8.32.
Is CVE-2019-9564 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2019-9564 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2019-9564?
CVE-2019-9564 affects Wyze Cam Pan v2, Wyze Cam v2, Wyze Cam v3.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.