PT-2021-9689 · Xiaomi · Xiaomi Router Rm1800+1

Published

2021-04-08

·

Updated

2021-04-14

·

CVE-2020-14099

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xiaomi router AX1800 rom versions prior to 1.0.336 Xiaomi router RM1800 root versions prior to 1.0.26
Description The encryption scheme for user backup files uses hard-coded keys, potentially exposing sensitive information such as user passwords.
Recommendations For Xiaomi router AX1800 rom versions prior to 1.0.336, update to version 1.0.336 or later to resolve the issue. For Xiaomi router RM1800 root versions prior to 1.0.26, update to version 1.0.26 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14099

Affected Products

Xiaomi Router Ax1800
Xiaomi Router Rm1800