PT-2024-12093 · Xiaomi · Xiaomi Router Ax9000

Published

2024-08-26

·

Updated

2024-10-08

·

CVE-2023-26315

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xiaomi router AX9000 versions all
Description The issue is a post-authentication command injection vulnerability caused by the lack of input filtering, allowing an attacker to obtain root access to the device.
Recommendations Update to the latest firmware version to secure the device. As a temporary workaround, consider restricting access to the device until a patch is available.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-26315

Affected Products

Xiaomi Router Ax9000