mi records
101 published records for vendor mi.
Researcher profile
- Entered KEV
- 1 · 1%
- Weaponized
- 1 · 1%
- Pre-auth RCE
- 24
- With a fix record
- 9.9%
- Median publish → KEV
- 1302 days
Recurring classes
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere11
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')7
- CWE-787 Out-of-bounds Write5
- CWE-345 Insufficient Verification of Data Authenticity4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
101 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
83Now | CVE-2018-6065Weaponized | Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3google · chrome · CWE-190 | High8.8 | KEV | 60.3% | Nov 14, 2018 |
51Plan | CVE-2019-18370Proof of concept | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.mi · millet router 3g firmware · CWE-78 | Critical9.8 | — | 40.3% | Oct 23, 2019 |
47Plan | CVE-2019-18371Proof of concept | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.mi · millet router 3g firmware · CWE-22 | High7.5 | — | 55.9% | Oct 23, 2019 |
42Plan | CVE-2018-16130No exploit | System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via themi · miwifi os · CWE-78 | High8.8 | — | 24.0% | Nov 27, 2018 |
42Plan | CVE-2018-13023No exploit | System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via mi · miwifi os · CWE-78 | High8.8 | — | 24.0% | Nov 27, 2018 |
41Plan | CVE-2023-26315No exploit | Xiaomi router has a command injection vulnerability after authorizationmi · ax9000 firmware · CWE-78 | High8.8 | — | 19.4% | Aug 26, 2024 |
41Plan | CVE-2020-14100No exploit | In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution.mi · r3600 firmware · CWE-77 | Critical9.8 | — | 5.6% | Sep 11, 2020 |
40Plan | CVE-2018-14060No exploit | OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices almi · xiaomi r3d firmware · CWE-78 | Critical9.8 | — | 4.5% | Jul 14, 2018 |
40Plan | CVE-2018-14010No exploit | OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15mi · xiaomi r3p firmware · CWE-78 | Critical9.8 | — | 4.5% | Jul 14, 2018 |
40Plan | CVE-2020-14119No exploit | There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on mi · ax3600 · CWE-77 | Critical9.8 | — | 3.0% | Sep 16, 2021 |
40Plan | CVE-2020-10561No exploit | An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138.mi · mijia inkjet printer firmware · CWE-77 | Critical9.8 | — | 2.5% | Jun 24, 2020 |
40Plan | CVE-2020-14095No exploit | In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to mi · xiaomi r3600 firmware · CWE-787 | Critical9.8 | — | 2.3% | Jun 24, 2020 |
40Plan | CVE-2020-14094No exploit | In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow ormi · xiaomi r3600 firmware · CWE-787 | Critical9.8 | — | 2.3% | Jun 24, 2020 |
40Plan | CVE-2020-14124No exploit | There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM versmi · ax3600 firmware · CWE-120 | Critical9.8 | — | 1.8% | Sep 16, 2021 |
39Monitor | CVE-2024-4406Proof of concept | Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerabilitymi · xiaomi 13 pro firmware · CWE-79 | Critical9.6 | — | 2.2% | May 2, 2024 |
39Monitor | CVE-2020-11960No exploit | Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to exmi · xiaomi r3600 firmware | Critical9.8 | — | 1.4% | Jun 24, 2020 |
39Monitor | CVE-2019-15913No exploit | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices.mi · dgnwg03lm firmware · CWE-639 | Critical9.8 | — | 1.3% | Dec 20, 2019 |
39Monitor | CVE-2020-14096No exploit | Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.mi · xiaomi ai speaker firmware · CWE-119 | Critical9.8 | — | 1.2% | Sep 11, 2020 |
39Monitor | CVE-2020-14115No exploit | A command injection vulnerability exists in the Xiaomi Router AX3600.mi · ax3600 firmware · CWE-345 | Critical9.8 | — | 1.1% | Mar 10, 2022 |
39Monitor | CVE-2023-26317No exploit | Xiaomi router external request interface has command injectionmi · xiaomi router firmware · CWE-78 | Critical9.8 | — | 1.1% | Aug 2, 2023 |
39Monitor | CVE-2018-18698No exploit | An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices.mi · xiaomi mi-a1 firmware · CWE-522 | Critical9.8 | — | 1.1% | Dec 24, 2018 |
39Monitor | CVE-2020-14129No exploit | A logic vulnerability exists in a Xiaomi product.mi · xiaomi | Critical9.8 | — | 1.0% | Oct 11, 2022 |
39Monitor | CVE-2020-14131No exploit | The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professmi · xiaomi | Critical9.8 | — | 0.9% | Oct 11, 2022 |
39Monitor | CVE-2023-26322No exploit | GetApps application has code execution vulnerabilitymi · getapps · CWE-94 | Critical9.8 | — | 0.8% | Aug 28, 2024 |
39Monitor | CVE-2023-26324No exploit | GetApps application has code execution vulnerabilitymi · getapps · CWE-94 | Critical9.8 | — | 0.6% | Aug 28, 2024 |
- CVE-2018-606583Now
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3
HighCVSS 8.8KEVWeaponizedEPSS 60%google · chromeNov 14, 2018
- CVE-2019-1837051Plan
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.
CriticalCVSS 9.8Proof of conceptEPSS 40%mi · millet router 3g firmwareOct 23, 2019
- CVE-2019-1837147Plan
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.
HighCVSS 7.5Proof of conceptEPSS 56%mi · millet router 3g firmwareOct 23, 2019
- CVE-2018-1613042Plan
System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the
HighCVSS 8.8No exploitEPSS 24%mi · miwifi osNov 27, 2018
- CVE-2018-1302342Plan
System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via
HighCVSS 8.8No exploitEPSS 24%mi · miwifi osNov 27, 2018
- CVE-2023-2631541Plan
Xiaomi router has a command injection vulnerability after authorization
HighCVSS 8.8No exploitEPSS 19%mi · ax9000 firmwareAug 26, 2024
- CVE-2020-1410041Plan
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution.
CriticalCVSS 9.8No exploitEPSS 6%mi · r3600 firmwareSep 11, 2020
- CVE-2018-1406040Plan
OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices al
CriticalCVSS 9.8No exploitEPSS 5%mi · xiaomi r3d firmwareJul 14, 2018
- CVE-2018-1401040Plan
OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15
CriticalCVSS 9.8No exploitEPSS 5%mi · xiaomi r3p firmwareJul 14, 2018
- CVE-2020-1411940Plan
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on
CriticalCVSS 9.8No exploitEPSS 3%mi · ax3600Sep 16, 2021
- CVE-2020-1056140Plan
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138.
CriticalCVSS 9.8No exploitEPSS 2%mi · mijia inkjet printer firmwareJun 24, 2020
- CVE-2020-1409540Plan
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to
CriticalCVSS 9.8No exploitEPSS 2%mi · xiaomi r3600 firmwareJun 24, 2020
- CVE-2020-1409440Plan
In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or
CriticalCVSS 9.8No exploitEPSS 2%mi · xiaomi r3600 firmwareJun 24, 2020
- CVE-2020-1412440Plan
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM vers
CriticalCVSS 9.8No exploitEPSS 2%mi · ax3600 firmwareSep 16, 2021
- CVE-2024-440639Monitor
Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability
CriticalCVSS 9.6Proof of conceptEPSS 2%mi · xiaomi 13 pro firmwareMay 2, 2024
- CVE-2020-1196039Monitor
Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to ex
CriticalCVSS 9.8No exploitEPSS 1%mi · xiaomi r3600 firmwareJun 24, 2020
- CVE-2019-1591339Monitor
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices.
CriticalCVSS 9.8No exploitEPSS 1%mi · dgnwg03lm firmwareDec 20, 2019
- CVE-2020-1409639Monitor
Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.
CriticalCVSS 9.8No exploitEPSS 1%mi · xiaomi ai speaker firmwareSep 11, 2020
- CVE-2020-1411539Monitor
A command injection vulnerability exists in the Xiaomi Router AX3600.
CriticalCVSS 9.8No exploitEPSS 1%mi · ax3600 firmwareMar 10, 2022
- CVE-2023-2631739Monitor
Xiaomi router external request interface has command injection
CriticalCVSS 9.8No exploitEPSS 1%mi · xiaomi router firmwareAug 2, 2023
- CVE-2018-1869839Monitor
An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices.
CriticalCVSS 9.8No exploitEPSS 1%mi · xiaomi mi-a1 firmwareDec 24, 2018
- CVE-2020-1412939Monitor
A logic vulnerability exists in a Xiaomi product.
CriticalCVSS 9.8No exploitEPSS 1%mi · xiaomiOct 11, 2022
- CVE-2020-1413139Monitor
The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and profess
CriticalCVSS 9.8No exploitEPSS 1%mi · xiaomiOct 11, 2022
- CVE-2023-2632239Monitor
GetApps application has code execution vulnerability
CriticalCVSS 9.8No exploitEPSS 1%mi · getappsAug 28, 2024
- CVE-2023-2632439Monitor
GetApps application has code execution vulnerability
CriticalCVSS 9.8No exploitEPSS 1%mi · getappsAug 28, 2024