Skip to main content

Vendor archive

mi CVEs

Beta · best-effort

101 CVEs tagged to vendor mi18 Critical, 40 High, 36 Medium, 7 Low, 0 Unrated.

CVE-2024-45348

Published Sep 23, 2024

Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit th…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26324

Published Aug 28, 2024

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26323

Published Aug 28, 2024

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26322

Published Aug 28, 2024

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26321

Published Aug 28, 2024

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can b…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26315

Published Aug 26, 2024

The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37664

Published Jun 17, 2024

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37663

Published Jun 17, 2024

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remot…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4406

Published May 2, 2024

Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4405

Published May 2, 2024

Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26317

Published Aug 2, 2023

Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exp…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26316

Published Aug 2, 2023

A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14140

Published Mar 29, 2023

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access con…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14131

Published Oct 11, 2022

The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security tea…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14129

Published Oct 11, 2022

A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief ele…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14126

Published Jul 22, 2022

Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14114

Published Jul 22, 2022

information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14123

Published Apr 22, 2022

There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14122

Published Apr 21, 2022

Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 101 CVEsPage 1 of 5