First published: Thu Sep 16 2021(Updated: )
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Ax3600 | <1.1.12 | |
Mi Ax3600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14119.
The affected software is Xiaomi router AX3600 with rom version rom < 1.1.12.
The severity of CVE-2020-14119 is critical, with a severity value of 9.8.
The vulnerability can be exploited through command injection in the addMeshNode interface of xqnetwork.lua, allowing command execution under administrator authority.
Yes, a fix is available by updating the Xiaomi router AX3600 to rom version 1.1.12 or higher.