Skip to content
Noroxi

mi records

101 published records for vendor mi.

All records

101 records
  • Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3

    HighCVSS 8.8KEVWeaponizedEPSS 60%

    google · chromeNov 14, 2018

  • An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.

    CriticalCVSS 9.8Proof of conceptEPSS 40%

    mi · millet router 3g firmwareOct 23, 2019

  • An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.

    HighCVSS 7.5Proof of conceptEPSS 56%

    mi · millet router 3g firmwareOct 23, 2019

  • System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the

    HighCVSS 8.8No exploitEPSS 24%

    mi · miwifi osNov 27, 2018

  • System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via

    HighCVSS 8.8No exploitEPSS 24%

    mi · miwifi osNov 27, 2018

  • Xiaomi router has a command injection vulnerability after authorization

    HighCVSS 8.8No exploitEPSS 19%

    mi · ax9000 firmwareAug 26, 2024

  • In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution.

    CriticalCVSS 9.8No exploitEPSS 6%

    mi · r3600 firmwareSep 11, 2020

  • OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices al

    CriticalCVSS 9.8No exploitEPSS 5%

    mi · xiaomi r3d firmwareJul 14, 2018

  • OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15

    CriticalCVSS 9.8No exploitEPSS 5%

    mi · xiaomi r3p firmwareJul 14, 2018

  • There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on

    CriticalCVSS 9.8No exploitEPSS 3%

    mi · ax3600Sep 16, 2021

  • An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138.

    CriticalCVSS 9.8No exploitEPSS 2%

    mi · mijia inkjet printer firmwareJun 24, 2020

  • In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to

    CriticalCVSS 9.8No exploitEPSS 2%

    mi · xiaomi r3600 firmwareJun 24, 2020

  • In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or

    CriticalCVSS 9.8No exploitEPSS 2%

    mi · xiaomi r3600 firmwareJun 24, 2020

  • There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM vers

    CriticalCVSS 9.8No exploitEPSS 2%

    mi · ax3600 firmwareSep 16, 2021

  • CVE-2024-4406
    39Monitor

    Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability

    CriticalCVSS 9.6Proof of conceptEPSS 2%

    mi · xiaomi 13 pro firmwareMay 2, 2024

  • Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to ex

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · xiaomi r3600 firmwareJun 24, 2020

  • An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices.

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · dgnwg03lm firmwareDec 20, 2019

  • Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · xiaomi ai speaker firmwareSep 11, 2020

  • A command injection vulnerability exists in the Xiaomi Router AX3600.

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · ax3600 firmwareMar 10, 2022

  • Xiaomi router external request interface has command injection

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · xiaomi router firmwareAug 2, 2023

  • An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices.

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · xiaomi mi-a1 firmwareDec 24, 2018

  • A logic vulnerability exists in a Xiaomi product.

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · xiaomiOct 11, 2022

  • The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and profess

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · xiaomiOct 11, 2022

  • GetApps application has code execution vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · getappsAug 28, 2024

  • GetApps application has code execution vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    mi · getappsAug 28, 2024