← Back

Mi

mi

101 CVEs • 148 products

Products (148)

Click to collapse
Toggle
Miui
miui
Mi Browser
mi_browser
Miwifi Os
miwifi_os
Xiaomi
xiaomi
Mi6 Browser
mi6_browser
Miui Firmware
miui_firmware
Mi App Store
mi_app_store
Getapps
getapps
Xiaomi R3
xiaomi_r3
Mint Browser
mint_browser
Mi 5s Firmware
mi_5s_firmware
M365 Firmware
m365_firmware
Stock Browser
stock_browser
Mix Firmware
mix_firmware
Pad 4 Firmware
pad_4_firmware
A3 Firmware
a3_firmware
R3600 Firmware
r3600_firmware
Ax3600
ax3600
Content Center
content_center
Smarthome
smarthome
Sound
sound
Xiaomi Cloud
xiaomi_cloud
File Manager
file_manager
App Market
app_market
Xiaomi R3p
xiaomi_r3p
Xiaomi R3c
xiaomi_r3c
Xiaomi R3d
xiaomi_r3d
Mi Router 3
mi_router_3
Mi A2 Lite
mi_a2_lite
Redmi 6
redmi_6
Xiaomi Mi A1
xiaomi_mi-a1
Mi Mix 2
mi_mix_2
Mi 5s
mi_5s
M365
m365
Mi 5s Plus
mi_5s_plus
Redmi 7
redmi_7
Redmi Note 7
redmi_note_7
Redmi 6a
redmi_6a
Redmi S2
redmi_s2

CVEs (101)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mi
1Redmi 5 Firmware
Nov 21, 2024
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Xiaomi Redmi 5 Android device with a build fingerprint of xiaomi/vince/vince:7.1.2/N2G47H/V9.5.4.0.NEGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1,...Show more
The Xiaomi Redmi 5 Android device with a build fingerprint of xiaomi/vince/vince:7.1.2/N2G47H/V9.5.4.0.NEGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1711_201803291645) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.Show less
1Mi
1Redmi 6 Firmware
Nov 21, 2024
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.f...Show more
The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006) that allows any app co-located on the device to programmatically disable and enable Wi-Fi, Bluetooth, and GPS without the corresponding access permission through an exported interface.Show less
1Mi
1Millet Router 3g Firmware
Nov 21, 2024
Oct 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/downlo...Show more
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.Show less
1Mi
1Millet Router 3g Firmware
Nov 21, 2024
Oct 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents o...Show more
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.Show less
1Mi
1Xiaomi Millet Firmware
Nov 21, 2024
Sep 18, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle attack may lead to partial data leakage or malicious file writing.
1Mi
19Redmi 4a Firmware
Redmi 5 Plus FirmwareRedmi 6 Firmware+16 more
Nov 21, 2024
Jun 7, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history v...Show more
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.Show less
6Fujitsu
GoogleMi+3 more
8Aquos Zeta Sh 04f Firmware
Arrows Nx F05 F FirmwareGalaxy S4 Firmware+5 more
Nov 21, 2024
Jun 6, 2019
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop tab...Show more
Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.Show less
1Mi
1Mi6 Browser
Nov 21, 2024
Jun 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must v...Show more
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WebAssembly.Instance method. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7466.Show less
1Mi
1M365 Firmware
Nov 21, 2024
May 31, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentication check. Other affected commands inclu...Show more
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentication check. Other affected commands include suddenly braking, locking, and unlocking.Show less
1Mi
1Mi 5s Firmware
Nov 21, 2024
Apr 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEMS ultrasound attack.
1Mi
2Mi Browser
Mint Browser
Nov 21, 2024
Apr 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of a...Show more
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user.Show less
1Mi
1Mi Mix 2 Firmware
Nov 21, 2024
Feb 17, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0 causes a system crash via IOCTL 0x4008c575 (aka decimal 1074316661).
1Mi
1Xiaomi Mi A1 Firmware
Nov 21, 2024
Dec 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat during the process of setting up the phone as a hotspot.
1Mi
2Mi A2 Lite Firmware
Redmi 6 Firmware
Nov 21, 2024
Dec 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc f...Show more
The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.Show less
1Mi
1Miwifi Os
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter.
1Mi
1Miwifi Os
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter.
1Mi
1Miwifi Os
Nov 21, 2024
Nov 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary JavaScript via a modified URL path.
4Debian
GoogleMi+1 more
6Chrome
Debian LinuxEnterprise Linux Desktop+3 more
Oct 24, 2025
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a c...Show more
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.Show less
1Mi
1Xiaomi Miwifi Xiaomi 55dd Firmware
Nov 21, 2024
Sep 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to retrieve the contents of an arbitrary external URL and return those con...Show more
An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to retrieve the contents of an arbitrary external URL and return those contents in its own response. If a domain name (containing a random string) is used in the HTTP Host header, the application performs an HTTP request to the specified domain. The response from that request is then included in the application's own response.Show less
1Mi
1Xiaomi R3d Firmware
Nov 21, 2024
Jul 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.