CVE-2024-45348: Xiaomi Router AX9000 has a post-authorization command injection vulnerability
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45348?
CVE-2024-45348 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-45348?
To fix CVE-2024-45348, users should update their Xiaomi Router AX9000 firmware to the latest version beyond 1.0.174.
What type of vulnerability is CVE-2024-45348?
CVE-2024-45348 is a post-authorization command injection vulnerability that allows for executing arbitrary commands.
Who is affected by CVE-2024-45348?
CVE-2024-45348 affects users of the Xiaomi Router AX9000 running firmware version 1.0.174 or earlier.
Can CVE-2024-45348 be exploited remotely?
Yes, CVE-2024-45348 can be exploited by attackers remotely due to the lack of input validation in the affected device.