Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mdz 25 Dt Firmware MEDIUM 6.8
CVE-2020-8994

An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then th…

No fix yet
Fix from $1,600 2020-03-05
Mi Browser HIGH 8.8
CVE-2019-13322

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction …

Fix: 10.4.0+
Fix from $1,950 2020-02-10
Mi Browser HIGH 8.0
CVE-2019-13321

This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User inte…

Fix: 10.4.0+
Fix from $1,950 2020-02-10
Dgnwg03lm Firmware CRITICAL 9.8
CVE-2019-15913

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communic…

No fix yet
Fix from $2,300 2019-12-20
Dgnwg03lm Firmware HIGH 7.5
CVE-2019-15914

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin pro…

No fix yet
Fix from $1,950 2019-12-20
Dgnwg03lm Firmware HIGH 7.5
CVE-2019-15915

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to…

No fix yet
Fix from $1,950 2019-12-20
A2 Lite Firmware MEDIUM 5.5
CVE-2019-15468

The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys cont…

Mitigation only
Fix from $1,600 2019-11-14
Pad 4 Firmware MEDIUM 5.5
CVE-2019-15469

The Xiaomi Mi Pad 4 Android device with a build fingerprint of Xiaomi/clover/clover:8.1.0/OPM1.171019.019/V9.6.26.0.ODJCNFD:user/release-keys contain…

Mitigation only
Fix from $1,600 2019-11-14
Redmi Note 6 Pro Firmware MEDIUM 5.5
CVE-2019-15470

The Xiaomi Redmi Note 6 Pro Android device with a build fingerprint of xiaomi/tulip/tulip:8.1.0/OPM1.171019.011/V10.2.2.0.OEKMIXM:user/release-keys c…

Mitigation only
Fix from $1,600 2019-11-14
Mix 2s Firmware MEDIUM 5.5
CVE-2019-15471

The Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys cont…

Mitigation only
Fix from $1,600 2019-11-14
A2 Lite Firmware MEDIUM 5.5
CVE-2019-15472

The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys cont…

Mitigation only
Fix from $1,600 2019-11-14
A2 Lite Firmware MEDIUM 5.5
CVE-2019-15473

The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/jasmine/jasmine_sprout:9/PKQ1.180904.001/V10.0.2.0.PDIMIFJ:user/release-keys …

Mitigation only
Fix from $1,600 2019-11-14
Cepheus Firmware MEDIUM 5.5
CVE-2019-15474

The Xiaomi Cepheus Android device with a build fingerprint of Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys contains a…

Mitigation only
Fix from $1,600 2019-11-14
A3 Firmware MEDIUM 5.5
CVE-2019-15475

The Xiaomi Mi A3 Android device with a build fingerprint of xiaomi/onc_eea/onc:9/PKQ1.181021.001/V10.2.8.0.PFLEUXM:user/release-keys contains a pre-i…

Mitigation only
Fix from $1,600 2019-11-14
Millet Router 3g Firmware CRITICAL 9.8
CVE-2019-18370EPSS 40%

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application us…

Fix: 2.28.23+
Fix from $2,300 2019-10-23
Millet Router 3g Firmware HIGH 7.5
CVE-2019-18371EPSS 56%

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via…

Fix: 2.28.23+
Fix from $1,950 2019-10-23
Xiaomi Millet Firmware HIGH 7.4
CVE-2019-15843

A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle a…

Mitigation only
Fix from $1,950 2019-09-18
Stock Browser MEDIUM 5.3
CVE-2018-20523EPSS 10%

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a …

No fix yet
Fix from $1,600 2019-06-07
Mi6 Browser HIGH 8.8
CVE-2019-6743

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser prior to 10.4.0. User interact…

Fix: 10.4.0+
Fix from $1,950 2019-06-03
M365 Firmware MEDIUM 6.5
CVE-2019-12500

The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands …

Fix: 1.5.1+
Fix from $1,600 2019-05-31
Mi 5s Firmware HIGH 7.5
CVE-2018-20823

The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEM…

No fix yet
Fix from $1,950 2019-04-25
Mi Browser MEDIUM 6.5
CVE-2019-10875

A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5…

No fix yet
Fix from $1,600 2019-04-05
Mi Mix 2 Firmware MEDIUM 5.5
CVE-2019-8413

On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0…

No fix yet
Fix from $1,600 2019-02-17
Xiaomi Mi A1 Firmware CRITICAL 9.8
CVE-2018-18698

An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat …

Mitigation only
Fix from $2,300 2018-12-24
Mi A2 Lite Firmware HIGH 7.5
CVE-2018-19939

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices throu…

Fix: after 2018-08-27
Fix from $1,950 2018-12-07
Miwifi Os HIGH 8.8
CVE-2018-13023EPSS 24%

System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "time…

No fix yet
Fix from $1,950 2018-11-27
Miwifi Os HIGH 8.8
CVE-2018-16130EPSS 24%

System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload…

No fix yet
Fix from $1,950 2018-11-27
Miwifi Os MEDIUM 6.1
CVE-2018-13022

Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary JavaScript via a m…

No fix yet
Fix from $1,600 2018-11-27
Xiaomi Miwifi Xiaomi 55dd Firmware HIGH 7.5
CVE-2018-16307

An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to …

No fix yet
Fix from $1,950 2018-09-05
Xiaomi R3p Firmware CRITICAL 9.8
CVE-2018-14010

OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D…

Fix: 2.12.15 / 2.14.5+
Fix from $2,300 2018-07-15