Junglewise Threat Intelligence

CVE-2026-12192: GALAYOU Y4 buffer overflow in Web Server

CVE-2026-12192 · Severity: high · CVSS 8.8 · Published 2026-06-15

Executive brief

A security vulnerability exists in the GALAYOU Y4 security camera (version 1.0.0) that could allow an attacker on the same local network to take control of the device. By exploiting a flaw in the camera's internal web server, an attacker could cause the system to crash or execute unauthorized commands. This could lead to a complete loss of privacy, unauthorized access to video feeds, or the device being used as a foothold for further attacks on the local network.

Technical details

A classic buffer overflow (CWE-120/CWE-119) exists within the web server component of the GALAYOU Y4 security camera, version 1.0.0. The vulnerability is triggered by sending specially crafted requests to an unknown function of the web server. An attacker located on the same local network (Adjacent vector) can exploit this without authentication to achieve remote code execution or cause a denial-of-service (system crash). As of the advisory date, the exploit is publicly available, and the vendor has not responded to disclosure attempts, meaning no official patch is currently available.

Affected products

  • GALAYOU Y4 1.0.0

Timeline

  • 2026-06-15: advisory: NVD publication date
  • 2026-06-15: disclosed: Public disclosure of the exploit

References