First published: Mon Aug 26 2024(Updated: )
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Mi Ax9000 Firmware | >=1.0.0<1.0.174 | |
Mi Ax9000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26315 is classified as a high severity vulnerability due to the potential for attackers to gain root access to the affected device.
To remediate CVE-2023-26315, update the Xiaomi AX9000 router firmware to a version later than 1.0.174.
CVE-2023-26315 specifically affects the Xiaomi AX9000 router running firmware versions from 1.0.0 to 1.0.174.
CVE-2023-26315 is a post-authentication command injection vulnerability caused by a lack of input filtering.
Yes, attackers can exploit CVE-2023-26315 remotely if they have access to the network where the device is located.