Записи mi
101 опубликованных записей вендора mi.
Профиль для исследователя
- Попали в KEV
- 1 · 1 %
- С эксплойтом
- 1 · 1 %
- Pre-auth RCE
- 24
- С записью об исправлении
- 9,9 %
- Медиана: публикация → KEV
- 1302 дн.
Повторяющиеся классы
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere11
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')7
- CWE-787 Out-of-bounds Write5
- CWE-345 Insufficient Verification of Data Authenticity4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
101 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
83Срочно | CVE-2018-6065Готовый эксплойт | Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3google · chrome · CWE-190 | Высокая8,8 | KEV | 60,3 % | 14 нояб. 2018 г. |
51В плане | CVE-2019-18370Proof of concept | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.mi · millet router 3g firmware · CWE-78 | Критическая9,8 | — | 40,3 % | 23 окт. 2019 г. |
47В плане | CVE-2019-18371Proof of concept | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.mi · millet router 3g firmware · CWE-22 | Высокая7,5 | — | 55,9 % | 23 окт. 2019 г. |
42В плане | CVE-2018-16130Эксплойта нет | System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via themi · miwifi os · CWE-78 | Высокая8,8 | — | 24,0 % | 27 нояб. 2018 г. |
42В плане | CVE-2018-13023Эксплойта нет | System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via mi · miwifi os · CWE-78 | Высокая8,8 | — | 24,0 % | 27 нояб. 2018 г. |
41В плане | CVE-2023-26315Эксплойта нет | Xiaomi router has a command injection vulnerability after authorizationmi · ax9000 firmware · CWE-78 | Высокая8,8 | — | 19,4 % | 26 авг. 2024 г. |
41В плане | CVE-2020-14100Эксплойта нет | In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution.mi · r3600 firmware · CWE-77 | Критическая9,8 | — | 5,6 % | 11 сент. 2020 г. |
40В плане | CVE-2018-14060Эксплойта нет | OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices almi · xiaomi r3d firmware · CWE-78 | Критическая9,8 | — | 4,5 % | 14 июл. 2018 г. |
40В плане | CVE-2018-14010Эксплойта нет | OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15mi · xiaomi r3p firmware · CWE-78 | Критическая9,8 | — | 4,5 % | 14 июл. 2018 г. |
40В плане | CVE-2020-14119Эксплойта нет | There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on mi · ax3600 · CWE-77 | Критическая9,8 | — | 3,0 % | 16 сент. 2021 г. |
40В плане | CVE-2020-10561Эксплойта нет | An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138.mi · mijia inkjet printer firmware · CWE-77 | Критическая9,8 | — | 2,5 % | 24 июн. 2020 г. |
40В плане | CVE-2020-14095Эксплойта нет | In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to mi · xiaomi r3600 firmware · CWE-787 | Критическая9,8 | — | 2,3 % | 24 июн. 2020 г. |
40В плане | CVE-2020-14094Эксплойта нет | In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow ormi · xiaomi r3600 firmware · CWE-787 | Критическая9,8 | — | 2,3 % | 24 июн. 2020 г. |
40В плане | CVE-2020-14124Эксплойта нет | There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM versmi · ax3600 firmware · CWE-120 | Критическая9,8 | — | 1,8 % | 16 сент. 2021 г. |
39Наблюдать | CVE-2024-4406Proof of concept | Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerabilitymi · xiaomi 13 pro firmware · CWE-79 | Критическая9,6 | — | 2,2 % | 2 мая 2024 г. |
39Наблюдать | CVE-2020-11960Эксплойта нет | Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to exmi · xiaomi r3600 firmware | Критическая9,8 | — | 1,4 % | 24 июн. 2020 г. |
39Наблюдать | CVE-2019-15913Эксплойта нет | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices.mi · dgnwg03lm firmware · CWE-639 | Критическая9,8 | — | 1,3 % | 20 дек. 2019 г. |
39Наблюдать | CVE-2020-14096Эксплойта нет | Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.mi · xiaomi ai speaker firmware · CWE-119 | Критическая9,8 | — | 1,2 % | 11 сент. 2020 г. |
39Наблюдать | CVE-2020-14115Эксплойта нет | A command injection vulnerability exists in the Xiaomi Router AX3600.mi · ax3600 firmware · CWE-345 | Критическая9,8 | — | 1,1 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2023-26317Эксплойта нет | Xiaomi router external request interface has command injectionmi · xiaomi router firmware · CWE-78 | Критическая9,8 | — | 1,1 % | 2 авг. 2023 г. |
39Наблюдать | CVE-2018-18698Эксплойта нет | An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices.mi · xiaomi mi-a1 firmware · CWE-522 | Критическая9,8 | — | 1,1 % | 24 дек. 2018 г. |
39Наблюдать | CVE-2020-14129Эксплойта нет | A logic vulnerability exists in a Xiaomi product.mi · xiaomi | Критическая9,8 | — | 1,0 % | 11 окт. 2022 г. |
39Наблюдать | CVE-2020-14131Эксплойта нет | The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professmi · xiaomi | Критическая9,8 | — | 0,9 % | 11 окт. 2022 г. |
39Наблюдать | CVE-2023-26322Эксплойта нет | GetApps application has code execution vulnerabilitymi · getapps · CWE-94 | Критическая9,8 | — | 0,8 % | 28 авг. 2024 г. |
39Наблюдать | CVE-2023-26324Эксплойта нет | GetApps application has code execution vulnerabilitymi · getapps · CWE-94 | Критическая9,8 | — | 0,6 % | 28 авг. 2024 г. |
- CVE-2018-606583Срочно
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 60 %google · chrome14 нояб. 2018 г.
- CVE-2019-1837051В плане
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.
КритическаяCVSS 9,8Proof of conceptEPSS 40 %mi · millet router 3g firmware23 окт. 2019 г.
- CVE-2019-1837147В плане
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.
ВысокаяCVSS 7,5Proof of conceptEPSS 56 %mi · millet router 3g firmware23 окт. 2019 г.
- CVE-2018-1613042В плане
System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the
ВысокаяCVSS 8,8Эксплойта нетEPSS 24 %mi · miwifi os27 нояб. 2018 г.
- CVE-2018-1302342В плане
System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via
ВысокаяCVSS 8,8Эксплойта нетEPSS 24 %mi · miwifi os27 нояб. 2018 г.
- CVE-2023-2631541В плане
Xiaomi router has a command injection vulnerability after authorization
ВысокаяCVSS 8,8Эксплойта нетEPSS 19 %mi · ax9000 firmware26 авг. 2024 г.
- CVE-2020-1410041В плане
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %mi · r3600 firmware11 сент. 2020 г.
- CVE-2018-1406040В плане
OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices al
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mi · xiaomi r3d firmware14 июл. 2018 г.
- CVE-2018-1401040В плане
OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mi · xiaomi r3p firmware14 июл. 2018 г.
- CVE-2020-1411940В плане
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mi · ax360016 сент. 2021 г.
- CVE-2020-1056140В плане
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mi · mijia inkjet printer firmware24 июн. 2020 г.
- CVE-2020-1409540В плане
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mi · xiaomi r3600 firmware24 июн. 2020 г.
- CVE-2020-1409440В плане
In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mi · xiaomi r3600 firmware24 июн. 2020 г.
- CVE-2020-1412440В плане
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM vers
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mi · ax3600 firmware16 сент. 2021 г.
- CVE-2024-440639Наблюдать
Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability
КритическаяCVSS 9,6Proof of conceptEPSS 2 %mi · xiaomi 13 pro firmware2 мая 2024 г.
- CVE-2020-1196039Наблюдать
Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to ex
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · xiaomi r3600 firmware24 июн. 2020 г.
- CVE-2019-1591339Наблюдать
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · dgnwg03lm firmware20 дек. 2019 г.
- CVE-2020-1409639Наблюдать
Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · xiaomi ai speaker firmware11 сент. 2020 г.
- CVE-2020-1411539Наблюдать
A command injection vulnerability exists in the Xiaomi Router AX3600.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · ax3600 firmware10 мар. 2022 г.
- CVE-2023-2631739Наблюдать
Xiaomi router external request interface has command injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · xiaomi router firmware2 авг. 2023 г.
- CVE-2018-1869839Наблюдать
An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · xiaomi mi-a1 firmware24 дек. 2018 г.
- CVE-2020-1412939Наблюдать
A logic vulnerability exists in a Xiaomi product.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · xiaomi11 окт. 2022 г.
- CVE-2020-1413139Наблюдать
The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and profess
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · xiaomi11 окт. 2022 г.
- CVE-2023-2632239Наблюдать
GetApps application has code execution vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · getapps28 авг. 2024 г.
- CVE-2023-2632439Наблюдать
GetApps application has code execution vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mi · getapps28 авг. 2024 г.