First published: Thu Apr 08 2021(Updated: )
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a user's password.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Ax1800 Firmware | <1.0.336 | |
Mi Ax1800 | ||
Mi Rm1800 Firmware | <1.0.26 | |
Mi Rm1800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14099.
The severity of CVE-2020-14099 is high (7.5).
AX1800 router rom version < 1.0.336 and RM1800 router root version < 1.0.26 are affected by CVE-2020-14099.
CVE-2020-14099 can expose sensitive information such as a user's password.
Upgrade your AX1800 router rom version to 1.0.336 or higher or upgrade your RM1800 router root version to 1.0.26 or higher.