Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-91957
HistorySep 18, 2021 - 12:00 a.m.

Xiaomi AX3600 Command Injection Vulnerability

2021-09-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
xiaomi
ax3600
command injection
vulnerability
router
parameter validation
administrator privileges
cnvd

EPSS

0.002

Percentile

58.8%

Xiaomi AX3600 is a router.A command injection vulnerability exists in the xqnetwork.lua addMeshNode interface, which is caused by insufficient parameter validation. An attacker could use this vulnerability to inject commands to execute with administrator privileges.

EPSS

0.002

Percentile

58.8%

Related for CNVD-2021-91957