First published: Wed Jan 13 2021(Updated: )
Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Redmi Ax6 Firmware | <1.0.18 | |
Mi Redmi Ax6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-14097.
The severity of CVE-2020-14097 is high (7.5).
The Xiaomi router AX6 with ROM version < 1.0.18 is affected by CVE-2020-14097.
CVE-2020-14097 allows unauthorized downloading of specific paths due to a misconfigured nginx server.
Yes, updating the Xiaomi router AX6 firmware to version 1.0.18 or later will fix CVE-2020-14097.