CVE-2020-14124: Buffer Overflow
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14124?
CVE-2020-14124 is a vulnerability with a severity rating of critical and a CVSS score of 9.8. It is a buffer overflow in librsa.so called by the getwifipwdurl interface on Xiaomi router AX3600 with ROM version < 1.1.12.
How does CVE-2020-14124 affect Xiaomi router AX3600?
CVE-2020-14124 affects Xiaomi router AX3600 with ROM version < 1.1.12, allowing code execution due to a buffer overflow in librsa.so called by the getwifipwdurl interface.
What is the severity of CVE-2020-14124?
CVE-2020-14124 has a severity rating of critical.
How can I fix CVE-2020-14124?
To fix CVE-2020-14124, update the ROM version of Xiaomi router AX3600 to 1.1.12 or higher.
Where can I find more information about CVE-2020-14124?
You can find more information about CVE-2020-14124 on the Xiaomi Trust Center website at https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=17.