In Xiaomi router R3600 ROM version<1.0.66, filters in the setWAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.
Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface getconfigresult without authentication
Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in cupload interface let attacker able to extract malicious file under any location in /tmp, lead to possible RCE and DoS
An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50.
In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code execution.