Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ax3600 Firmware HIGH 7.8
CVE-2020-14111

A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection…

Fix: 1.1.15+
Fix from $1,950 2022-03-10
Ax6000 Firmware MEDIUM 5.3
CVE-2020-14112

Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can expl…

Fix: 1.0.56+
Fix from $1,600 2022-03-10
Ax3600 Firmware HIGH 7.8
CVE-2020-14110

AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web back…

Fix: 1.0.67+
Fix from $1,950 2022-01-18
Xiaomi Mirror Screen HIGH 7.5
CVE-2020-14107

A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.

Fix: 12.4.8.2+
Fix from $1,950 2022-01-18
Ax3600 CRITICAL 9.8
CVE-2020-14119

There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi ro…

Fix: 1.1.12+
Fix from $2,300 2021-09-16
Ax3600 Firmware CRITICAL 9.8
CVE-2020-14124

There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom<…

Fix: after 1.1.12
Fix from $2,300 2021-09-16
Ax3600 Firmware HIGH 7.2
CVE-2020-14109

There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router …

Fix: after 1.1.12
Fix from $1,950 2021-09-16
Xiaomi MEDIUM 5.3
CVE-2020-14130

Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Versio…

Fix: 3.0.210809+
Fix from $1,600 2021-09-16
Mi True Wireless Earbuds Basic 2 Firmware MEDIUM 6.5
CVE-2021-31610

The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing atta…

Mitigation only
Fix from $1,600 2021-09-07
Miui MEDIUM 5.5
CVE-2020-14105

The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.

Fix: 2020.01.15+
Fix from $1,600 2021-04-20
Miui MEDIUM 5.5
CVE-2020-14103

The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.

Fix: 2020.01.15+
Fix from $1,600 2021-04-08
Miui MEDIUM 5.5
CVE-2020-14106

The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.…

Fix: 2021.01.26+
Fix from $1,600 2021-04-08
Ax3600 Firmware HIGH 8.1
CVE-2020-14104

A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.

Fix: after 1.0.50
Fix from $1,950 2021-04-08
Ax1800 Firmware HIGH 7.5
CVE-2020-14099

On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys,…

Fix: 1.0.26 / 1.0.336+
Fix from $1,950 2021-04-08
Redmi Ax6 Firmware HIGH 7.5
CVE-2020-14097

Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18.

Fix: 1.0.18+
Fix from $1,950 2021-01-13
Ax1800 Firmware HIGH 7.5
CVE-2020-14098

The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router A…

Fix: 1.0.26 / 1.0.336+
Fix from $1,950 2021-01-13
Ax1800 Firmware HIGH 7.5
CVE-2020-14101

The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.33…

Fix: 1.0.26 / 1.0.336+
Fix from $1,950 2021-01-13
Ax1800 Firmware HIGH 7.2
CVE-2020-14102

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This aff…

Fix: 1.0.26 / 1.0.336+
Fix from $1,950 2021-01-13
Xiaomi Ai Speaker Firmware CRITICAL 9.8
CVE-2020-14096

Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.

Fix: 1.59.6+
Fix from $2,300 2020-09-11
R3600 Firmware CRITICAL 9.8
CVE-2020-14100EPSS 5%

In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator…

Fix: 1.0.66+
Fix from $2,300 2020-09-11
Xiaomi R3600 Firmware HIGH 7.5
CVE-2020-11961

Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authen…

Fix: 1.0.20+
Fix from $1,950 2020-06-24
Mijia Inkjet Printer Firmware CRITICAL 9.8
CVE-2020-10561

An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resul…

Fix: 3.4.6_0138+
Fix from $2,300 2020-06-24
Xiaomi R3600 Firmware CRITICAL 9.8
CVE-2020-11960

Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to extract mal…

Fix: 1.0.20+
Fix from $2,300 2020-06-24
Xiaomi R3600 Firmware HIGH 7.5
CVE-2020-11959

An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50.

Fix: 1.0.20+
Fix from $1,950 2020-06-24
Xiaomi R3600 Firmware CRITICAL 9.8
CVE-2020-14094

In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote c…

Fix: 1.0.20+
Fix from $2,300 2020-06-24
Xiaomi R3600 Firmware CRITICAL 9.8
CVE-2020-14095

In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack o…

Fix: 1.0.20+
Fix from $2,300 2020-06-24
Xiaomi Xiaoai Speaker Pro Lx06 Firmware MEDIUM 6.8
CVE-2020-10262

An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.58.10. Attackers can activate the failsafe mode during the boot process, and use the mi_c…

No fix yet
Fix from $1,600 2020-04-08
Xiaomi Xiaoai Speaker Pro Lx06 Firmware MEDIUM 6.8
CVE-2020-10263

An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) …

No fix yet
Fix from $1,600 2020-04-08
Miui Firmware HIGH 7.3
CVE-2020-9531

An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. In the Web resources of GetApps(com.xiaomi.mipicks), the parameters passed in are r…

Mitigation only
Fix from $1,950 2020-03-06
Miui Firmware MEDIUM 6.5
CVE-2020-9530

An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of…

Mitigation only
Fix from $1,600 2020-03-06