CVE-2023-26319: Xiaomi Router administration interface vulnerability leads command injection and stack overflow
Published Oct 11, 2023
·Updated
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
Affected Software
4 affected components
Mi Xiaomi Router Ax3200 Firmware<2023.2
Mi Xiaomi Router Ax3200
All of the following
Mi Xiaomi Router Ax3200 Firmware<2023.2
Mi Xiaomi Router Ax3200
Event History
Oct 11, 2023
CVE Published
via MITRE·06:45 AM
Data Sourced
via MITRE·06:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-26319.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Improper Neutralization of Special Elements used in a Command (Command Injection) vulnerability in Xiaomi Xiaomi Router allows Command Injection.'
3
What is the severity of CVE-2023-26319?
The severity of CVE-2023-26319 is high with a severity value of 7.2.
4
Which software is affected by CVE-2023-26319?
The Mi Xiaomi Router Ax3200 Firmware with versions up to exclusive 2023.2 is affected by CVE-2023-26319.
5
How can I fix CVE-2023-26319?
Apply the latest firmware update provided by Xiaomi to fix CVE-2023-26319.