ZeroHour

CVE-2020-14102

CVSS 3.1
7.2 high
EPSS
2%p78
Published
()
Modified
Description

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

Vendors
mi
Products
ax1800 firmware, rm1800 firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.