High severity7.5NVD Advisory· Published Mar 29, 2023· Updated Jun 17, 2026
CVE-2020-14140
CVE-2020-14140
Description
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Xiaomi/router firmwaredescription
- Range: 2020
Patches
Vulnerability mechanics
References
1- trust.mi.com/zh-CN/misrc/bulletins/advisorynvdVendor Advisory
News mentions
0No linked articles in our index yet.