PT-2024-31577 · Xiaomi · Xiaomi Router Ax9000

Published

2024-09-23

·

Updated

2024-11-25

·

CVE-2024-45348

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xiaomi Router AX9000 version 1.0.173
Description The issue is caused by the lack of validation of user input, allowing an attacker to exploit it and execute arbitrary code. This is a post-authorization command injection vulnerability, enabling remote attacks.
Recommendations For version 1.0.173, patch immediately to resolve the issue. Additionally, monitor for exploit development to stay informed about potential threats. As a temporary workaround, consider restricting access to the router until a patch is applied.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-45348

Affected Products

Xiaomi Router Ax9000