CVE-2020-14099: High severity mi ax1800 firmware vulnerability
Published Apr 8, 2021
·Updated
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a user's password.
Affected Software
4 affected components
Mi Ax1800 Firmware<1.0.336
Mi AX1800
Mi Rm1800 Firmware<1.0.26
Mi RM1800
Event History
Apr 8, 2021
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-14099.
2
What is the severity of CVE-2020-14099?
The severity of CVE-2020-14099 is high (7.5).
3
Which software versions are affected by CVE-2020-14099?
AX1800 router rom version < 1.0.336 and RM1800 router root version < 1.0.26 are affected by CVE-2020-14099.
4
What is the impact of CVE-2020-14099?
CVE-2020-14099 can expose sensitive information such as a user's password.
5
How can I fix CVE-2020-14099?
Upgrade your AX1800 router rom version to 1.0.336 or higher or upgrade your RM1800 router root version to 1.0.26 or higher.