CVE-2020-14094: Critical severity mi r3600 vulnerability
Published Jun 24, 2020
·Updated
In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.
Affected Software
2 affected components
Mi Xiaomi R3600 Firmware<1.0.20
Mi Xiaomi R3600
Event History
Jun 24, 2020
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Xiaomi router issue?
The vulnerability ID for this issue is CVE-2020-14094.
2
What is the severity of CVE-2020-14094?
The severity of CVE-2020-14094 is critical with a CVSS score of 9.8.
3
Which Xiaomi router model is affected by CVE-2020-14094?
The Xiaomi router model R3600 with ROM version<1.0.20 is affected by CVE-2020-14094.
4
How can the connection service be injected through the web interface?
The connection service can be injected through the web interface in Xiaomi router R3600 ROM version<1.0.20, resulting in stack overflow or remote code execution.
5
Is there a fix available for CVE-2020-14094?
Upgrading the Xiaomi router firmware to version 1.0.20 or higher will fix CVE-2020-14094.