CVE-2023-26315: Xiaomi router has a command injection vulnerability after authorization
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26315?
CVE-2023-26315 is classified as a high severity vulnerability due to the potential for attackers to gain root access to the affected device.
How do I fix CVE-2023-26315?
To remediate CVE-2023-26315, update the Xiaomi AX9000 router firmware to a version later than 1.0.174.
What devices are affected by CVE-2023-26315?
CVE-2023-26315 specifically affects the Xiaomi AX9000 router running firmware versions from 1.0.0 to 1.0.174.
What is the nature of the vulnerability in CVE-2023-26315?
CVE-2023-26315 is a post-authentication command injection vulnerability caused by a lack of input filtering.
Can CVE-2023-26315 be exploited remotely?
Yes, attackers can exploit CVE-2023-26315 remotely if they have access to the network where the device is located.