Router AX3600
by Xiaomi
CVEs (16)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-14115 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. | ||
| CVE-2020-14124 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2021 | There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12. | ||
| CVE-2020-14119 | Cri | 0.64 | 9.8 | 0.03 | Sep 16, 2021 | There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12 | ||
| CVE-2020-14100 | Cri | 0.64 | 9.8 | 0.06 | Sep 11, 2020 | In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability. | ||
| CVE-2020-11960 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2020 | Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to extract malicious file under any location in /tmp, lead to possible RCE and DoS | ||
| CVE-2020-14104 | Hig | 0.53 | 8.1 | 0.01 | Apr 8, 2021 | A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50. | ||
| CVE-2020-14111 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. | ||
| CVE-2020-14101 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26. | ||
| CVE-2020-14098 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26. | ||
| CVE-2020-14097 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18. | ||
| CVE-2020-11959 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2020 | An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50. | ||
| CVE-2020-14109 | Hig | 0.47 | 7.2 | 0.02 | Sep 16, 2021 | There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12 | ||
| CVE-2020-14102 | Hig | 0.47 | 7.2 | 0.02 | Jan 13, 2021 | There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26. | ||
| CVE-2023-26315 | Med | 0.44 | 6.5 | 0.19 | Aug 26, 2024 | The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device. | ||
| CVE-2024-45348 | Med | 0.42 | 6.4 | 0.01 | Sep 23, 2024 | Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code. | ||
| CVE-2020-14112 | Med | 0.35 | 5.3 | 0.01 | Mar 10, 2022 | Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can exploit this vulnerability to download part of the files in Xiaomi Router AX6000. |
- risk 0.64cvss 9.8epss 0.01
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
- risk 0.64cvss 9.8epss 0.02
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
- risk 0.64cvss 9.8epss 0.03
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12
- risk 0.64cvss 9.8epss 0.06
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.
- risk 0.64cvss 9.8epss 0.01
Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to extract malicious file under any location in /tmp, lead to possible RCE and DoS
- risk 0.53cvss 8.1epss 0.01
A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.
- risk 0.51cvss 7.8epss 0.00
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
- risk 0.49cvss 7.5epss 0.01
The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
- risk 0.49cvss 7.5epss 0.01
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
- risk 0.49cvss 7.5epss 0.01
Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18.
- risk 0.49cvss 7.5epss 0.01
An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50.
- risk 0.47cvss 7.2epss 0.02
There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12
- risk 0.47cvss 7.2epss 0.02
There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
- risk 0.44cvss 6.5epss 0.19
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
- risk 0.42cvss 6.4epss 0.01
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.
- risk 0.35cvss 5.3epss 0.01
Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can exploit this vulnerability to download part of the files in Xiaomi Router AX6000.