First published: Wed Jan 13 2021(Updated: )
There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Ax1800 Firmware | <1.0.336 | |
Mi Ax1800 | ||
Mi Rm1800 Firmware | <1.0.26 | |
Mi Rm1800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-14102.
CVE-2020-14102 has a severity of 7.2 (High).
CVE-2020-14102 affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
CVE-2020-14102 allows the administrator user to obtain root privileges on the router.
More information about CVE-2020-14102 can be found at https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=23&locale=en.