ZDI-CAN-22559: ZDI-24-417: Xiaomi Pro 13 isUrlMatchLevel Permissive List of Allowed Inputs Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-26322.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22559?
ZDI-CAN-22559 has been rated with a high severity due to its potential to allow remote code execution.
How do I fix ZDI-CAN-22559?
To fix ZDI-CAN-22559, users should update their Xiaomi Pro 13 smartphones to the latest firmware released by Xiaomi.
What type of vulnerability is ZDI-CAN-22559?
ZDI-CAN-22559 is a remote code execution vulnerability that requires user interaction to exploit.
Who is affected by ZDI-CAN-22559?
Only users of the Xiaomi Pro 13 smartphones are affected by ZDI-CAN-22559.
Can ZDI-CAN-22559 be exploited without user interaction?
No, ZDI-CAN-22559 requires the user to visit a malicious page or open a malicious file for exploitation.