PT-2020-12203 · Xiaomi · Xiaomi Mi Jia Ink-Jet Printer
Published
2020-06-24
·
Updated
2021-07-21
·
CVE-2020-10561
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xiaomi Mi Jia ink-jet printer versions prior to 3.4.6 0138
Description
An issue was discovered in the Xiaomi Mi Jia ink-jet printer, where injecting parameters to the ippserver through the web management background results in command execution vulnerabilities.
Recommendations
For versions prior to 3.4.6 0138, update to version 3.4.6 0138 or later to resolve the issue. As a temporary workaround, consider restricting access to the web management background to minimize the risk of exploitation. Avoid using the ippserver parameter in the affected API endpoint until the issue is resolved.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xiaomi Mi Jia Ink-Jet Printer