PT-2021-9691 · Xiaomi · Xiaomi Router Rm1800+1

Published

2021-01-13

·

Updated

2021-01-19

·

CVE-2020-14102

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Xiaomi router AX1800rom versions prior to 1.0.336 Xiaomi router RM1800 root versions prior to 1.0.26
Description The issue is related to command injection when processing the hostname, allowing an administrator user to gain root privilege of the router.
Recommendations For Xiaomi router AX1800rom versions prior to 1.0.336, update to version 1.0.336 or later. For Xiaomi router RM1800 root versions prior to 1.0.26, update to version 1.0.26 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14102

Affected Products

Xiaomi Router Ax1800
Xiaomi Router Rm1800