CVE-2020-14100: Command Injection
Published Sep 11, 2020
·Updated
In Xiaomi router R3600 ROM version<1.0.66, filters in the setWAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.
Affected Software
2 affected components
Mi R3600 Firmware<1.0.66
Mi R3600
Event History
Sep 11, 2020
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-14100?
CVE-2020-14100 is a vulnerability in Xiaomi router R3600 ROM version<1.0.66 where filters in the set_WAN6 interface can be bypassed, allowing remote code execution.
2
How severe is CVE-2020-14100?
CVE-2020-14100 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2020-14100 affect Xiaomi router R3600?
CVE-2020-14100 allows remote code execution on Xiaomi router R3600 ROM version<1.0.66, providing the router administrator with root access.
4
Is Xiaomi router R3600 vulnerable to CVE-2020-14100?
Yes, Xiaomi router R3600 with ROM version<1.0.66 is vulnerable to CVE-2020-14100.
5
How can I fix CVE-2020-14100?
To fix CVE-2020-14100, update the Xiaomi router R3600 firmware to version 1.0.66 or later.