PT-2020-12953 · Xiaomi · Xiaomi Router Ax3600

Published

2020-06-24

·

Updated

2021-07-21

·

CVE-2020-11961

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xiaomi router R3600 ROM versions prior to 1.0.50
Description The issue is related to a sensitive information leakage caused by an insecure interface. Specifically, the get config result interface lacks authentication, which can lead to the exposure of sensitive information.
Recommendations For versions prior to 1.0.50, update to version 1.0.50 or later to resolve the issue. As a temporary workaround, consider restricting access to the get config result interface until a patch is applied.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11961

Affected Products

Xiaomi Router Ax3600