PT-2020-20415 · Xiaomi · Xiaomi Ai Speaker
Published
2020-03-05
·
Updated
2021-07-21
·
CVE-2020-8994
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
XIAOMI AI speaker MDZ-25-DT versions 1.34.36 through 1.40.14
Description
An issue was discovered in the XIAOMI AI speaker, allowing attackers to gain root shell access by exploiting the UART interface. This access enables them to read Wi-Fi SSID or password, dialogue text files between users and the speaker, and use Text-To-Speech tools to mimic the speaker's voice for social engineering attacks. Additionally, attackers can eavesdrop on users, record audio, delete the entire system, modify system files, stop the voice assistant service, and start the SSH service as a backdoor.
Recommendations
For versions 1.34.36 through 1.40.14, consider disabling the UART interface access as a temporary workaround until a patch is available. Restrict access to the Text-To-Speech tools and SSH service to minimize the risk of exploitation. Avoid using the Wi-Fi SSID or password storage on the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xiaomi Ai Speaker