First published: Mon Mar 07 2022(Updated: )
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Ax3600 Firmware | <1.0.67 | |
Mi Ax3600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this command injection vulnerability is CVE-2020-14115.
The command injection vulnerability in the Xiaomi Router AX3600 is caused by a lack of inspection for incoming data detection.
Attackers can exploit this command injection vulnerability to execute code on the affected Xiaomi Router AX3600.
The Mi Ax3600 Firmware versions up to and excluding 1.0.67 are affected by this vulnerability.
The severity rating of this vulnerability is critical, with a CVSS score of 9.8.