PT-2020-12203 · Xiaomi · Xiaomi Mi Jia Ink-Jet Printer

Published

2020-06-24

·

Updated

2021-07-21

·

CVE-2020-10561

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xiaomi Mi Jia ink-jet printer versions prior to 3.4.6 0138
Description An issue was discovered in the Xiaomi Mi Jia ink-jet printer, where injecting parameters to the ippserver through the web management background results in command execution vulnerabilities.
Recommendations For versions prior to 3.4.6 0138, update to version 3.4.6 0138 or later to resolve the issue. As a temporary workaround, consider restricting access to the web management background to minimize the risk of exploitation. Avoid using the ippserver parameter in the affected API endpoint until the issue is resolved.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10561

Affected Products

Xiaomi Mi Jia Ink-Jet Printer