First published: Wed Jun 24 2020(Updated: )
Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to extract malicious file under any location in /tmp, lead to possible RCE and DoS
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Xiaomi R3600 Firmware | <1.0.20 | |
Mi Xiaomi R3600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11960.
The severity of CVE-2020-11960 is critical with a severity value of 9.8.
Xiaomi router R3600 ROM before 1.0.50 is affected by CVE-2020-11960.
CVE-2020-11960 allows an attacker to extract a malicious file under any location in /tmp, leading to possible remote code execution (RCE) and denial of service (DoS) attacks.
Yes, upgrading to Xiaomi router R3600 ROM version 1.0.50 or later fixes CVE-2020-11960.