Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2020-14115

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
Attacker Value
Unknown

CVE-2020-14111

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
Attacker Value
Unknown

CVE-2020-14110

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.
Attacker Value
Unknown

CVE-2020-14124

Disclosure Date: September 16, 2021 (last updated February 23, 2025)
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
Attacker Value
Unknown

CVE-2020-14109

Disclosure Date: September 16, 2021 (last updated February 23, 2025)
There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12
Attacker Value
Unknown

CVE-2020-14104

Disclosure Date: April 08, 2021 (last updated February 22, 2025)
A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.