CVE-2020-8994: Medium severity Mi Mdz-25-dt Firmware vulnerability
An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then they can read Wi-Fi SSID or password, read the dialogue text files between users and XIAOMI AI speaker, use Text-To-Speech tools pretend XIAOMI speakers' voice achieve social engineering attacks, eavesdrop on users and record what XIAOMI AI speaker hears, delete the entire XIAOMI AI speaker system, modify system files, stop voice assistant service, start the XIAOMI AI speaker’s SSH service as a backdoor
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8994?
CVE-2020-8994 is classified as a critical vulnerability due to the potential for attackers to gain root access to the device.
How do I fix CVE-2020-8994?
To mitigate CVE-2020-8994, update your Xiaomi AI speaker firmware to a version that is not vulnerable, such as versions beyond 1.40.14.
What systems are affected by CVE-2020-8994?
CVE-2020-8994 affects Xiaomi AI speaker models using firmware versions 1.34.36 and 1.40.14.
What can an attacker do if they exploit CVE-2020-8994?
An attacker exploiting CVE-2020-8994 can gain root shell access and retrieve sensitive information such as Wi-Fi credentials and dialogue text files.
Is there a known workaround for CVE-2020-8994?
There is no reliable workaround for CVE-2020-8994 other than updating to a secure firmware version.