First published: Tue Nov 27 2018(Updated: )
System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Miwifi OS | =2.22.15 | |
Mi Router 3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16130 is considered a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2018-16130, update the Xiaomi Mi Router 3 firmware to a version later than 2.22.15.
If exploited, CVE-2018-16130 allows an attacker to execute arbitrary system commands on the vulnerable device.
CVE-2018-16130 affects the Xiaomi Mi Router 3 running firmware version 2.22.15.
CVE-2018-16130 occurs due to improper handling of input in the 'payload' URL parameter, leading to system command injection.