VYPR

Vendor CVEs

Xiaomi

All CVEs

109 total · sorted by risk
  • CVE-2019-18370CriOct 23, 2019
    risk 0.67cvss 9.8epss 0.40

    An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the…

  • CVE-2026-29515CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.00

    MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which…

  • CVE-2020-14131CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi…

  • CVE-2020-14129CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.

  • CVE-2020-14115CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

  • CVE-2020-14124CriSep 16, 2021
    risk 0.64cvss 9.8epss 0.02

    There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.

  • CVE-2020-14119CriSep 16, 2021
    risk 0.64cvss 9.8epss 0.03

    There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12

  • CVE-2020-14100CriSep 11, 2020
    risk 0.64cvss 9.8epss 0.05

    In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.

  • CVE-2020-14096CriSep 11, 2020
    risk 0.64cvss 9.8epss 0.01

    Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.

  • CVE-2020-11960CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to extract malicious file under any location in /tmp, lead to possible RCE and DoS

  • CVE-2020-10561CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities.

  • CVE-2020-14095CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code execution.

  • CVE-2020-14094CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.

  • CVE-2019-15913CriDec 20, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with…

  • CVE-2018-18698CriDec 24, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat during the process of setting up the phone as a hotspot.

  • CVE-2018-14060CriJul 15, 2018
    risk 0.64cvss 9.8epss 0.05

    OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.

  • CVE-2018-14010CriJul 15, 2018
    risk 0.64cvss 9.8epss 0.05

    OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.

  • CVE-2024-4406CriMay 2, 2024
    risk 0.63cvss 9.6epss 0.02

    Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this…

  • CVE-2024-45347CriJun 23, 2025
    risk 0.62cvss 9.6epss 0.00

    An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.

  • CVE-2024-4405CriMay 2, 2024
    risk 0.62cvss 9.6epss 0.01

    Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability…

  • CVE-2018-16130HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.24

    System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter.

  • CVE-2018-13023HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.24

    System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter.

  • CVE-2024-45352HigMar 27, 2025
    risk 0.57cvss 8.8epss 0.00

    An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

  • CVE-2023-26324HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

  • CVE-2023-26322HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

  • CVE-2024-45346HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.00

    The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security…

  • CVE-2022-31277HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.

  • CVE-2020-14120HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.00

    Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, and attackers can induce users to install a malicious app and use the vulnerability to achieve…

  • CVE-2019-13322HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…

  • CVE-2019-6743HigJun 3, 2019
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2020-14104HigApr 8, 2021
    risk 0.53cvss 8.1epss 0.01

    A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.

  • CVE-2019-18371HigOct 23, 2019
    risk 0.53cvss 7.5epss 0.56

    An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability,…

  • CVE-2019-13321HigFeb 10, 2020
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw…

  • CVE-2024-45351HigMar 26, 2025
    risk 0.51cvss 7.8epss 0.00

    A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

  • CVE-2020-14111HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

  • CVE-2020-14110HigJan 18, 2022
    risk 0.51cvss 7.8epss 0.00

    AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.

  • CVE-2023-26323HigAug 28, 2024
    risk 0.49cvss 7.6epss 0.01

    A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

  • CVE-2023-26320HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

  • CVE-2020-14140HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.01

    When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the…

  • CVE-2020-14126HigJul 22, 2022
    risk 0.49cvss 7.5epss 0.01

    Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.

  • CVE-2020-14114HigJul 22, 2022
    risk 0.49cvss 7.5epss 0.01

    information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.

  • CVE-2020-14125HigJun 8, 2022
    risk 0.49cvss 7.5epss 0.07

    A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited by attackers to make denial of service.

  • CVE-2020-14123HigApr 22, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module…

  • CVE-2020-14099HigApr 8, 2021
    risk 0.49cvss 7.5epss 0.01

    On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a user's password.

  • CVE-2020-14101HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

  • CVE-2020-14098HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

  • CVE-2020-14097HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18.

  • CVE-2020-11961HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authentication

  • CVE-2020-11959HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50.

  • CVE-2019-15915HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

Page 1 of 3