First published: Tue Nov 27 2018(Updated: )
System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Miwifi OS | =2.22.15 | |
Mi Router 3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13023 has a medium severity rating due to the potential for system command injection.
To mitigate CVE-2018-13023, users should update their Xiaomi Mi Router 3 firmware to a secure version beyond 2.22.15.
CVE-2018-13023 specifically affects Xiaomi Mi Router 3 running MiWifi OS version 2.22.15.
Yes, CVE-2018-13023 could potentially allow attackers to execute arbitrary system commands, leading to remote access.
Yes, there are publicly available proof-of-concept exploits demonstrating the vulnerability exploited through the 'timeout' URL parameter.