First published: Wed Jun 24 2020(Updated: )
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code execution.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Xiaomi R3600 Firmware | <1.0.20 | |
Mi Xiaomi R3600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14095 is an injection vulnerability in Xiaomi router R3600 with ROM version<1.0.20, which can result in stack overflow or remote code execution through the web interface.
CVE-2020-14095 affects Xiaomi router R3600 with ROM version<1.0.20 by allowing an attacker to inject malicious code through the web interface, leading to a stack overflow or remote code execution.
CVE-2020-14095 has a severity rating of 9.8 (Critical).
To fix CVE-2020-14095, update your Xiaomi router R3600 firmware to version 1.0.20 or above.
You can find more information about CVE-2020-14095 at the following link: [CVE-2020-14095](https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=18&locale=en)