First published: Wed Oct 11 2023(Updated: )
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
Credit: security@xiaomi.com security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Xiaomi Router Ax3200 Firmware | <2023.2 | |
Mi Xiaomi Router Ax3200 | ||
All of | ||
Mi Xiaomi Router Ax3200 Firmware | <2023.2 | |
Mi Xiaomi Router Ax3200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26320 is a Command Injection vulnerability in Xiaomi Xiaomi Router Ax3200 Firmware.
CVE-2023-26320 allows for Command Injection, which can potentially allow attackers to execute arbitrary commands on the router.
The severity of CVE-2023-26320 is high with a score of 8.1.
To fix the CVE-2023-26320 vulnerability, it is recommended to update the Xiaomi Router Ax3200 Firmware to version 2023.2 or a higher version.
More information about CVE-2023-26320 can be found in the advisory on the Xiaomi Trust website: https://trust.mi.com/misrc/bulletins/advisory?cveId=540