← Back

Mi

mi

101 CVEs • 148 products

Products (148)

Click to collapse
Toggle
Miui
miui
Mi Browser
mi_browser
Miwifi Os
miwifi_os
Xiaomi
xiaomi
Mi6 Browser
mi6_browser
Miui Firmware
miui_firmware
Mi App Store
mi_app_store
Getapps
getapps
Xiaomi R3
xiaomi_r3
Mint Browser
mint_browser
Mi 5s Firmware
mi_5s_firmware
M365 Firmware
m365_firmware
Stock Browser
stock_browser
Mix Firmware
mix_firmware
Pad 4 Firmware
pad_4_firmware
A3 Firmware
a3_firmware
R3600 Firmware
r3600_firmware
Ax3600
ax3600
Content Center
content_center
Smarthome
smarthome
Sound
sound
Xiaomi Cloud
xiaomi_cloud
File Manager
file_manager
App Market
app_market
Xiaomi R3p
xiaomi_r3p
Xiaomi R3c
xiaomi_r3c
Xiaomi R3d
xiaomi_r3d
Mi Router 3
mi_router_3
Mi A2 Lite
mi_a2_lite
Redmi 6
redmi_6
Xiaomi Mi A1
xiaomi_mi-a1
Mi Mix 2
mi_mix_2
Mi 5s
mi_5s
M365
m365
Mi 5s Plus
mi_5s_plus
Redmi 7
redmi_7
Redmi Note 7
redmi_note_7
Redmi 6a
redmi_6a
Redmi S2
redmi_s2

CVEs (101)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mi
4Xiaomi R3
Xiaomi R3c FirmwareXiaomi R3d Firmware+1 more
Nov 21, 2024
Jul 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D before 2.26.4 devices allows an attacker to execute any command via cr...Show more
OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.Show less