CVE-2024-45348
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.
Affected (1)
Products: Mi: Ax9000 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.174 |
| Running on/with | Platform Versions |
|---|---|
Mi Ax9000 | All versions |
References (1)
Source: security@xiaomi.com
Vendor Advisory
Timeline
No history available yet.