CVE-2020-11960: Critical severity mi r3600 vulnerability
Published Jun 24, 2020
·Updated
Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in cupload interface let attacker able to extract malicious file under any location in /tmp, lead to possible RCE and DoS
Affected Software
2 affected components
Mi Xiaomi R3600 Firmware<1.0.20
Mi Xiaomi R3600
Event History
Jun 24, 2020
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11960.
2
What is the severity of CVE-2020-11960?
The severity of CVE-2020-11960 is critical with a severity value of 9.8.
3
Which software is affected by CVE-2020-11960?
Xiaomi router R3600 ROM before 1.0.50 is affected by CVE-2020-11960.
4
How does CVE-2020-11960 impact the affected software?
CVE-2020-11960 allows an attacker to extract a malicious file under any location in /tmp, leading to possible remote code execution (RCE) and denial of service (DoS) attacks.
5
Is there a fix available for CVE-2020-11960?
Yes, upgrading to Xiaomi router R3600 ROM version 1.0.50 or later fixes CVE-2020-11960.