VYPR

Ax3600 Firmware

by Mi

CVEs (6)

  • CVE-2020-14115CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

  • CVE-2020-14124CriSep 16, 2021
    risk 0.64cvss 9.8epss 0.02

    There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.

  • CVE-2020-14104HigApr 8, 2021
    risk 0.53cvss 8.1epss 0.01

    A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.

  • CVE-2020-14111HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

  • CVE-2020-14110HigJan 18, 2022
    risk 0.51cvss 7.8epss 0.00

    AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.

  • CVE-2020-14109HigSep 16, 2021
    risk 0.47cvss 7.2epss 0.02

    There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12