CVE-2018-13023: OS Command Injection
Published Nov 27, 2018
·Updated
System command injection vulnerability in wifiaccess in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter.
Affected Software
2 affected components
Mi Miwifi Os=2.22.15
Mi Mi Router 3
Event History
Nov 27, 2018
CVE Published
08:29 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13023?
CVE-2018-13023 has a medium severity rating due to the potential for system command injection.
2
How do I fix CVE-2018-13023?
To mitigate CVE-2018-13023, users should update their Xiaomi Mi Router 3 firmware to a secure version beyond 2.22.15.
3
What systems are affected by CVE-2018-13023?
CVE-2018-13023 specifically affects Xiaomi Mi Router 3 running MiWifi OS version 2.22.15.
4
Can CVE-2018-13023 lead to remote access?
Yes, CVE-2018-13023 could potentially allow attackers to execute arbitrary system commands, leading to remote access.
5
Is there a proof-of-concept for CVE-2018-13023?
Yes, there are publicly available proof-of-concept exploits demonstrating the vulnerability exploited through the 'timeout' URL parameter.