ZeroHour

CVE-2023-26315

CVSS 3.1
8.8 high
EPSS
19%p97
Published
()
Modified
Description

The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.

Vendors
mi
Products
ax9000 firmware
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.