CVE-2020-14115: Command Injection
Published Mar 7, 2022
·Updated
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
Affected Software
2 affected components
Mi Ax3600 Firmware<1.0.67
Mi AX3600
Event History
Mar 7, 2022
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this command injection vulnerability?
The vulnerability ID of this command injection vulnerability is CVE-2020-14115.
2
What is the cause of this command injection vulnerability?
The command injection vulnerability in the Xiaomi Router AX3600 is caused by a lack of inspection for incoming data detection.
3
What can attackers do with this command injection vulnerability?
Attackers can exploit this command injection vulnerability to execute code on the affected Xiaomi Router AX3600.
4
Which software versions of the Xiaomi Router AX3600 are affected by this vulnerability?
The Mi Ax3600 Firmware versions up to and excluding 1.0.67 are affected by this vulnerability.
5
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is critical, with a CVSS score of 9.8.