CVE-2018-16307: Infoleak
An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi55DD Version 2.8.50 devices. It is possible to induce the application to retrieve the contents of an arbitrary external URL and return those contents in its own response. If a domain name (containing a random string) is used in the HTTP Host header, the application performs an HTTP request to the specified domain. The response from that request is then included in the application's own response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16307?
CVE-2018-16307 has a medium severity level due to its potential for unauthorized information retrieval.
How do I fix CVE-2018-16307?
To mitigate CVE-2018-16307, upgrade the Xiaomi MIWiFi firmware to a version that has addressed this vulnerability.
What devices are affected by CVE-2018-16307?
CVE-2018-16307 specifically affects Xiaomi MIWiFi Xiaomi_55DD devices running firmware version 2.8.50.
What is the impact of CVE-2018-16307?
The impact of CVE-2018-16307 includes the potential for an attacker to load and view the contents of an arbitrary external URL.
Is there any known exploit for CVE-2018-16307?
Yes, there are references indicating that CVE-2018-16307 can be exploited to induce the application to retrieve sensitive external resources.