CVE-2023-26320: Xiaomi Router external request interface vulnerability leads to stack overflow
Published Oct 11, 2023
·Updated
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
Affected Software
4 affected components
All of the following
Mi Xiaomi Router Ax3200 Firmware<2023.2
Mi Xiaomi Router Ax3200
Mi Xiaomi Router Ax3200 Firmware<2023.2
Mi Xiaomi Router Ax3200
Event History
Oct 11, 2023
CVE Published
via MITRE·06:49 AM
Data Sourced
via MITRE·06:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-26320?
CVE-2023-26320 is a Command Injection vulnerability in Xiaomi Xiaomi Router Ax3200 Firmware.
2
How does CVE-2023-26320 impact Xiaomi Xiaomi Router Ax3200 Firmware?
CVE-2023-26320 allows for Command Injection, which can potentially allow attackers to execute arbitrary commands on the router.
3
What is the severity of CVE-2023-26320?
The severity of CVE-2023-26320 is high with a score of 8.1.
4
How can I fix the CVE-2023-26320 vulnerability?
To fix the CVE-2023-26320 vulnerability, it is recommended to update the Xiaomi Router Ax3200 Firmware to version 2023.2 or a higher version.
5
Where can I find more information about CVE-2023-26320?
More information about CVE-2023-26320 can be found in the advisory on the Xiaomi Trust website: https://trust.mi.com/misrc/bulletins/advisory?cveId=540