CVE-2018-14060: Command Injection
Published Jul 15, 2018
·Updated
OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/setrouterwifiap on Xiaomi R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.
Affected Software
2 affected components
Mi Xiaomi R3d Firmware<2.26.4
Mi Xiaomi R3D
Event History
Jul 15, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14060?
The severity of CVE-2018-14060 is considered high due to the ability for attackers to execute arbitrary commands on affected devices.
2
How do I fix CVE-2018-14060?
To fix CVE-2018-14060, update the firmware of the Xiaomi R3D device to version 2.26.4 or later.
3
Which devices are affected by CVE-2018-14060?
CVE-2018-14060 affects Xiaomi R3D devices running firmware versions prior to 2.26.4.
4
What type of vulnerability is CVE-2018-14060?
CVE-2018-14060 is classified as an OS command injection vulnerability.
5
Can CVE-2018-14060 be exploited remotely?
Yes, CVE-2018-14060 can be exploited remotely if an attacker sends crafted JSON data to the vulnerable API.