First published: Thu Sep 16 2021(Updated: )
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Ax3600 Firmware | <=1.1.12 | |
Mi Ax3600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14124 is a vulnerability with a severity rating of critical and a CVSS score of 9.8. It is a buffer overflow in librsa.so called by the getwifipwdurl interface on Xiaomi router AX3600 with ROM version < 1.1.12.
CVE-2020-14124 affects Xiaomi router AX3600 with ROM version < 1.1.12, allowing code execution due to a buffer overflow in librsa.so called by the getwifipwdurl interface.
CVE-2020-14124 has a severity rating of critical.
To fix CVE-2020-14124, update the ROM version of Xiaomi router AX3600 to 1.1.12 or higher.
You can find more information about CVE-2020-14124 on the Xiaomi Trust Center website at https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=17.