CVE-2018-16130: OS Command Injection
Published Nov 27, 2018
·Updated
System command injection in requestmitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter.
Affected Software
2 affected components
Mi Miwifi Os=2.22.15
Mi Mi Router 3
Event History
Nov 27, 2018
CVE Published
08:29 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16130?
CVE-2018-16130 is considered a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2018-16130?
To fix CVE-2018-16130, update the Xiaomi Mi Router 3 firmware to a version later than 2.22.15.
3
What could happen if CVE-2018-16130 is exploited?
If exploited, CVE-2018-16130 allows an attacker to execute arbitrary system commands on the vulnerable device.
4
Which devices are affected by CVE-2018-16130?
CVE-2018-16130 affects the Xiaomi Mi Router 3 running firmware version 2.22.15.
5
How does CVE-2018-16130 occur?
CVE-2018-16130 occurs due to improper handling of input in the 'payload' URL parameter, leading to system command injection.