Lucene search

K
cvelistXiaomiCVELIST:CVE-2020-14140
HistoryMar 29, 2023 - 12:00 a.m.

CVE-2020-14140

2023-03-2900:00:00
Xiaomi
www.cve.org
3
xiaomi
firmware
update
wifi password
vulnerability
unauthenticated api
access control
background command injection

EPSS

0.001

Percentile

34.9%

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Xiaomi Multiple Devices",
    "versions": [
      {
        "version": "Xiaomi Multiple Devices, firmware update time in 2020-2022",
        "status": "affected"
      }
    ]
  }
]

EPSS

0.001

Percentile

34.9%

Related for CVELIST:CVE-2020-14140