CVE-2018-18698: Critical severity xiaomi mi a1 firmware vulnerability
Published Dec 24, 2018
·Updated
An issue was discovered on Xiaomi Mi A1 tissotsprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat during the process of setting up the phone as a hotspot.
Affected Software
2 affected components
Mi Xiaomi Mi-a1 Firmware
Mi Xiaomi Mi-a1
Event History
Dec 24, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18698?
CVE-2018-18698 has a moderate severity level due to the exposure of cleartext Wi-Fi passwords.
2
How do I fix CVE-2018-18698?
To mitigate CVE-2018-18698, ensure that your device is updated to the latest firmware that addresses this vulnerability.
3
Which devices are affected by CVE-2018-18698?
CVE-2018-18698 affects Xiaomi Mi A1 devices running specific firmware versions.
4
What type of data is exposed in CVE-2018-18698?
CVE-2018-18698 exposes cleartext Wi-Fi passwords during the hotspot setup process.
5
Is CVE-2018-18698 related to any specific software version?
Yes, CVE-2018-18698 specifically concerns Xiaomi Mi A1 devices running the firmware version OPM1.171019.026/V9.6.4.0.ODHMIFE.