First published: Fri Sep 11 2020(Updated: )
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi R3600 Firmware | <1.0.66 | |
Mi R3600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14100 is a vulnerability in Xiaomi router R3600 ROM version<1.0.66 where filters in the set_WAN6 interface can be bypassed, allowing remote code execution.
CVE-2020-14100 has a severity rating of 9.8, which is considered critical.
CVE-2020-14100 allows remote code execution on Xiaomi router R3600 ROM version<1.0.66, providing the router administrator with root access.
Yes, Xiaomi router R3600 with ROM version<1.0.66 is vulnerable to CVE-2020-14100.
To fix CVE-2020-14100, update the Xiaomi router R3600 firmware to version 1.0.66 or later.