CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data. |
1Mi 4Xiaomi R3 Xiaomi R3c FirmwareXiaomi R3d Firmware+1 moreNov 21, 2024 Jul 15, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D before 2.26.4 devices allows an attacker to execute any command via cr...Show more |