PT-2020-20415 · Xiaomi · Xiaomi Ai Speaker

Published

2020-03-05

·

Updated

2021-07-21

·

CVE-2020-8994

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XIAOMI AI speaker MDZ-25-DT versions 1.34.36 through 1.40.14
Description An issue was discovered in the XIAOMI AI speaker, allowing attackers to gain root shell access by exploiting the UART interface. This access enables them to read Wi-Fi SSID or password, dialogue text files between users and the speaker, and use Text-To-Speech tools to mimic the speaker's voice for social engineering attacks. Additionally, attackers can eavesdrop on users, record audio, delete the entire system, modify system files, stop the voice assistant service, and start the SSH service as a backdoor.
Recommendations For versions 1.34.36 through 1.40.14, consider disabling the UART interface access as a temporary workaround until a patch is available. Restrict access to the Text-To-Speech tools and SSH service to minimize the risk of exploitation. Avoid using the Wi-Fi SSID or password storage on the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8994

Affected Products

Xiaomi Ai Speaker