First published: Wed Jan 13 2021(Updated: )
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Ax1800 Firmware | <1.0.336 | |
Mi Ax1800 | ||
Mi Rm1800 Firmware | <1.0.26 | |
Mi Rm1800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14098
The severity rating of CVE-2020-14098 is high with a value of 7.5.
Xiaomi router AX1800rom version < 1.0.336 and Xiaomi router RM1800 root version < 1.0.26 are affected.
CVE-2020-14098 can be exploited by bypassing the login verification using the time synchronization issue after the router restarts.
To fix CVE-2020-14098, users should update their Xiaomi router AX1800rom and RM1800 firmware to versions 1.0.336 and 1.0.26 or above respectively.