The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
References
Link | Resource |
---|---|
https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=546 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
08 Oct 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-78 |
06 Sep 2024, 22:25
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mi ax9000
Mi Mi ax9000 Firmware |
|
CWE | CWE-77 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=546 - Vendor Advisory | |
CPE | cpe:2.3:h:mi:ax9000:-:*:*:*:*:*:*:* cpe:2.3:o:mi:ax9000_firmware:*:*:*:*:*:*:*:* |
|
Summary |
|
26 Aug 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-26 12:15
Updated : 2024-10-08 10:15
NVD link : CVE-2023-26315
Mitre link : CVE-2023-26315
CVE.ORG link : CVE-2023-26315
JSON object : View
Products Affected
mi
- ax9000_firmware
- ax9000