Search

Find a vulnerability

Search criteria

    58 vulnerabilities by mi

    CVE-2023-26324 (GCVE-0-2023-26324)

    Vulnerability from nvd – Published: 2024-08-28 07:28 – Updated: 2024-08-28 13:47
    VLAI
    Title
    GetApps application has code execution vulnerability
    Summary
    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:46 UTC
    CWE
    • A code execution vulnerability exists
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Xiaomi GetApps application Affected: GetApps application , ≤ 30.6.0.2 (custom)
    Create a notification for this product.
    xiaomi getapps_application Affected: 0 , ≤ 30.6.0.2 (custom)
        cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-05-06 06:01
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "getapps_application",
                "vendor": "xiaomi",
                "versions": [
                  {
                    "lessThanOrEqual": "30.6.0.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26324",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:46:06.441446Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T13:47:11.451Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "GetApps application",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "30.6.0.2",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "30.6.0.2",
                  "status": "affected",
                  "version": "GetApps application",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-05-06T06:01:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "GetApps application 30.6.0.2"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "A code execution vulnerability exists",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-28T07:35:40.482Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://https://trust.mi.com/misrc/bulletins/advisory?cveId=544"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GetApps application has code execution vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26324",
        "datePublished": "2024-08-28T07:28:35.809Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2024-08-28T13:47:11.451Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26323 (GCVE-0-2023-26323)

    Vulnerability from nvd – Published: 2024-08-28 07:53 – Updated: 2026-03-02 18:27
    VLAI
    Title
    Xiaomi App Market has a code execution vulnerability
    Summary
    A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:22 UTC
    CWE
    • a code execution vulnerability in Xiaomi App Store
    • CWE-95 - Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
    Impacted products
    Vendor Product Version
    Xiaomi App Market Affected: 1.0.0 , ≤ 4.57.4 (custom)
    Create a notification for this product.
    Date Public
    2024-03-14 02:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26323",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:22:30.333129Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-95",
                    "description": "CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code (\u0027Eval Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-02T18:27:06.704Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "App Market",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "4.58.2",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "4.57.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-03-14T02:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Xiaomi App Store APP 4.57.4"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "a code execution vulnerability in Xiaomi App Store",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-20T03:35:34.288Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=543"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Xiaomi App Market has a code execution vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26323",
        "datePublished": "2024-08-28T07:53:42.801Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2026-03-02T18:27:06.704Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-26322 (GCVE-0-2023-26322)

    Vulnerability from nvd – Published: 2024-08-28 07:59 – Updated: 2024-08-28 13:39
    VLAI
    Title
    GetApps application has code execution vulnerability
    Summary
    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:30 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Xiaomi GetApps application Affected: GetApps application , ≤ 31.2.5.0 (custom)
    Create a notification for this product.
    xiaomi getapps_application Affected: 0 , ≤ 31.2.5.0 (custom)
        cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "getapps_application",
                "vendor": "xiaomi",
                "versions": [
                  {
                    "lessThanOrEqual": "31.2.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26322",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:30:30.765435Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T13:39:52.719Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "GetApps application",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "32.0.0.1",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "31.2.5.0",
                  "status": "affected",
                  "version": "GetApps application",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-28T11:24:24.657Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=542"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GetApps application has code execution vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26322",
        "datePublished": "2024-08-28T07:59:26.998Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2024-08-28T13:39:52.719Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26321 (GCVE-0-2023-26321)

    Vulnerability from nvd – Published: 2024-08-28 07:51 – Updated: 2025-03-25 15:57
    VLAI
    Title
    The international version of Xiaomi File Manager has a path traversal vulnerability
    Summary
    A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:39 UTC
    CWE
    • A path traversal vulnerability exists
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Xiaomi Xiaomi File Manager App International Version Affected: Xiaomi File Manager App International Version , ≤ V1-210567 (custom)
    Create a notification for this product.
    mi file_manager Affected: 0 , ≤ v1-210586 (custom)
        cpe:2.3:a:mi:file_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-02-08 07:41
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mi:file_manager:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "file_manager",
                "vendor": "mi",
                "versions": [
                  {
                    "lessThanOrEqual": "v1-210586",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26321",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:39:58.176575Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-25T15:57:26.688Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Xiaomi File Manager App International Version",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "V1-210586",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "V1-210567",
                  "status": "affected",
                  "version": "Xiaomi File Manager App International Version",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-02-08T07:41:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Xiaomi File Manager App International Version V1-210567"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "PHYSICAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "A path traversal vulnerability exists",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-28T07:51:28.809Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=541"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "The international version of Xiaomi File Manager has a path traversal vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26321",
        "datePublished": "2024-08-28T07:51:28.809Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2025-03-25T15:57:26.688Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-27346 (GCVE-0-2023-27346)

    Vulnerability from nvd – Published: 2024-05-03 01:56 – Updated: 2024-09-18 18:28
    VLAI
    Title
    TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
    Summary
    TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of firmware images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-19703.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-16 19:02 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    TP-Link AX1800 Affected: Archer AX21(US)_V3_1.1.1 Build 20220603
    Create a notification for this product.
    mi ax1800_firmware Affected: 0 , < 3230219 (custom)
        cpe:2.3:o:mi:ax1800_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-03-31 20:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:mi:ax1800_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "ax1800_firmware",
                "vendor": "mi",
                "versions": [
                  {
                    "lessThan": "3230219",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-27346",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-16T19:02:06.476318Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-25T15:33:40.656Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T12:09:43.399Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "ZDI-23-377",
                "tags": [
                  "x_research-advisory",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-377/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "AX1800",
              "vendor": "TP-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "Archer AX21(US)_V3_1.1.1 Build 20220603"
                }
              ]
            }
          ],
          "dateAssigned": "2023-02-28T18:05:54.014Z",
          "datePublic": "2023-03-31T20:45:32.764Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the parsing of firmware images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.\n. Was ZDI-CAN-19703."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-18T18:28:03.839Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "name": "ZDI-23-377",
              "tags": [
                "x_research-advisory"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-377/"
            }
          ],
          "source": {
            "lang": "en",
            "value": "Kevin Wang"
          },
          "title": "TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2023-27346",
        "datePublished": "2024-05-03T01:56:05.862Z",
        "dateReserved": "2023-02-28T17:58:45.480Z",
        "dateUpdated": "2024-09-18T18:28:03.839Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26317 (GCVE-0-2023-26317)

    Vulnerability from nvd – Published: 2023-08-02 00:00 – Updated: 2024-10-16 20:07
    VLAI
    Title
    Xiaomi router external request interface has command injection
    Summary
    Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-16 19:56 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Xiaomi Xiaomi router Affected: Xiaomi Router Firmware version before 2023.2 , ≤ 2023.2 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.915Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=529"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26317",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-16T19:56:08.393776Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-16T20:07:44.750Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Xiaomi router",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "2023.4",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "2023.2",
                  "status": "affected",
                  "version": "Xiaomi Router Firmware version before 2023.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eXiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.\u003c/span\u003e\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-08T09:44:23.934Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=529"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Xiaomi router external request interface has command injection",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26317",
        "datePublished": "2023-08-02T00:00:00.000Z",
        "dateReserved": "2023-02-22T00:00:00.000Z",
        "dateUpdated": "2024-10-16T20:07:44.750Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26316 (GCVE-0-2023-26316)

    Vulnerability from nvd – Published: 2023-08-02 00:00 – Updated: 2024-09-27 21:58
    VLAI
    Summary
    A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-27 21:50 UTC
    CWE
    • XSS
    Impacted products
    Vendor Product Version
    n/a Xiaomi cloud service Application Affected: Xiaomi cloud service Application < 1.12.0.0.25
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:24.361Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=322"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26316",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-27T21:50:09.403135Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-27T21:58:10.819Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi cloud service Application",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi cloud service Application \u003c 1.12.0.0.25"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview\u0027s whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account\u0027s cookies."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "XSS",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-02T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=322"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26316",
        "datePublished": "2023-08-02T00:00:00.000Z",
        "dateReserved": "2023-02-22T00:00:00.000Z",
        "dateUpdated": "2024-09-27T21:58:10.819Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14140 (GCVE-0-2020-14140)

    Vulnerability from nvd – Published: 2023-03-29 00:00 – Updated: 2025-02-18 17:10
    VLAI
    Summary
    When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-18 17:09 UTC
    CWE
    • Unauthenticated API that can reveal WIFI password vulnerability
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    n/a Xiaomi Multiple Devices Affected: Xiaomi Multiple Devices, firmware update time in 2020-2022
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.012Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=506"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-14140",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-18T17:09:07.172437Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-306",
                    "description": "CWE-306 Missing Authentication for Critical Function",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-18T17:10:37.810Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi Multiple Devices",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi Multiple Devices, firmware update time in 2020-2022"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Unauthenticated API that can reveal WIFI password vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-03-29T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=506"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14140",
        "datePublished": "2023-03-29T00:00:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2025-02-18T17:10:37.810Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14131 (GCVE-0-2020-14131)

    Vulnerability from nvd – Published: 2022-10-11 00:00 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.
    Severity
    No CVSS data available.
    CWE
    • a lack of identity verification
    Impacted products
    Vendor Product Version
    n/a Xiaomi specific devices Affected: Xiaomi specific devices,Affected Version:11,Fixed Version:12
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.010Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=153"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi specific devices",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi specific devices,Affected Version:11,Fixed Version:12"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "a lack of identity verification",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-10-11T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=153"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14131",
        "datePublished": "2022-10-11T00:00:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:36.010Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14129 (GCVE-0-2020-14129)

    Vulnerability from nvd – Published: 2022-10-11 00:00 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.
    Severity
    No CVSS data available.
    CWE
    • Vulnerability logic vulnerability
    Impacted products
    Vendor Product Version
    n/a Xiaomi a certain APP Affected: Affected Version:3.4.5.18 Fixed Version:3.4.5.24
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.494Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=155"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi a certain APP",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Affected Version:3.4.5.18 Fixed Version:3.4.5.24"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Vulnerability logic vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-10-11T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=155"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14129",
        "datePublished": "2022-10-11T00:00:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:36.494Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14126 (GCVE-0-2020-14126)

    Vulnerability from nvd – Published: 2022-07-22 15:30 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.
    Severity
    No CVSS data available.
    CWE
    • Information leakage
    References
    Impacted products
    Vendor Product Version
    n/a Mi Sound APP Affected: Mi Sound APP <=2.2.40
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:35.966Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Mi Sound APP",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Mi Sound APP \u003c=2.2.40"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information leakage",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-22T15:30:39.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14126",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Mi Sound APP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Mi Sound APP \u003c=2.2.40"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information leakage"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14126",
        "datePublished": "2022-07-22T15:30:39.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:35.966Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14114 (GCVE-0-2020-14114)

    Vulnerability from nvd – Published: 2022-07-22 15:32 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.
    Severity
    No CVSS data available.
    CWE
    • Information leakage
    References
    Impacted products
    Vendor Product Version
    n/a Xiaomi SmartHome APP Affected: Xiaomi SmartHome APP <=6.4.701
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.202Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi SmartHome APP",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi SmartHome APP \u003c=6.4.701"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information leakage",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-22T15:32:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14114",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Xiaomi SmartHome APP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Xiaomi SmartHome APP \u003c=6.4.701"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information leakage"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14114",
        "datePublished": "2022-07-22T15:32:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:36.202Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14123 (GCVE-0-2020-14123)

    Vulnerability from nvd – Published: 2022-04-22 15:17 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges.
    Severity
    No CVSS data available.
    CWE
    • Pointer Double Free Vulnerability
    References
    Impacted products
    Vendor Product Version
    n/a MIUI Affected: MIUI version 12.5.2
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:35.902Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MIUI",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "MIUI version 12.5.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Pointer Double Free Vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-22T15:17:36.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14123",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MIUI",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "MIUI version 12.5.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Pointer Double Free Vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14123",
        "datePublished": "2022-04-22T15:17:36.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:35.902Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14122 (GCVE-0-2020-14122)

    Vulnerability from nvd – Published: 2022-04-21 17:27 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user information leakage.
    Severity
    No CVSS data available.
    CWE
    • Information leakage
    References
    Impacted products
    Vendor Product Version
    n/a MIUI Affected: MIUI version 12.5.2
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:35.958Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=147"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MIUI",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "MIUI version 12.5.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user information leakage."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information leakage",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-21T17:27:52.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=147"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14122",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MIUI",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "MIUI version 12.5.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user information leakage."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information leakage"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=147",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=147"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14122",
        "datePublished": "2022-04-21T17:27:52.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:35.958Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14121 (GCVE-0-2020-14121)

    Vulnerability from nvd – Published: 2022-04-21 17:25 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.
    Severity
    No CVSS data available.
    CWE
    • Business logic vulnerability
    References
    Impacted products
    Vendor Product Version
    n/a Mi App Store Affected: Mi App Store version 4.12.2
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:35.919Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=146"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Mi App Store",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Mi App Store version 4.12.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Business logic vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-21T17:25:10.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=146"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14121",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Mi App Store",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Mi App Store version 4.12.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Business logic vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=146",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=146"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14121",
        "datePublished": "2022-04-21T17:25:10.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:35.919Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14120 (GCVE-0-2020-14120)

    Vulnerability from nvd – Published: 2022-04-21 17:30 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, and attackers can induce users to install a malicious app and use the vulnerability to achieve elevated privileges, making the normal services of the system affected.
    Severity
    No CVSS data available.
    CWE
    • Permission bypass
    References
    Impacted products
    Vendor Product Version
    n/a MIUI Affected: MIUI version 12.5
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:35.755Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=145"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MIUI",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "MIUI version 12.5"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, and attackers can induce users to install a malicious app and use the vulnerability to achieve elevated privileges, making the normal services of the system affected."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Permission bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-21T17:30:37.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=145"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14120",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MIUI",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "MIUI version 12.5"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, and attackers can induce users to install a malicious app and use the vulnerability to achieve elevated privileges, making the normal services of the system affected."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Permission bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=145",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=145"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14120",
        "datePublished": "2022-04-21T17:30:37.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:35.755Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14118 (GCVE-0-2020-14118)

    Vulnerability from nvd – Published: 2022-04-21 17:33 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps.
    Severity
    No CVSS data available.
    CWE
    • Intent redirection vulnerability
    References
    Impacted products
    Vendor Product Version
    n/a Mi App Store Affected: Mi App Store version <4.10.0
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.051Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=144"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Mi App Store",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Mi App Store version \u003c4.10.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Intent redirection vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-21T17:33:02.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=144"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14118",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Mi App Store",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Mi App Store version \u003c4.10.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Intent redirection vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=144",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=144"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14118",
        "datePublished": "2022-04-21T17:33:02.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:36.051Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26322 (GCVE-0-2023-26322)

    Vulnerability from cvelistv5 – Published: 2024-08-28 07:59 – Updated: 2024-08-28 13:39
    VLAI
    Title
    GetApps application has code execution vulnerability
    Summary
    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:30 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Xiaomi GetApps application Affected: GetApps application , ≤ 31.2.5.0 (custom)
    Create a notification for this product.
    xiaomi getapps_application Affected: 0 , ≤ 31.2.5.0 (custom)
        cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "getapps_application",
                "vendor": "xiaomi",
                "versions": [
                  {
                    "lessThanOrEqual": "31.2.5.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26322",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:30:30.765435Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T13:39:52.719Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "GetApps application",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "32.0.0.1",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "31.2.5.0",
                  "status": "affected",
                  "version": "GetApps application",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-28T11:24:24.657Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=542"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GetApps application has code execution vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26322",
        "datePublished": "2024-08-28T07:59:26.998Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2024-08-28T13:39:52.719Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26323 (GCVE-0-2023-26323)

    Vulnerability from cvelistv5 – Published: 2024-08-28 07:53 – Updated: 2026-03-02 18:27
    VLAI
    Title
    Xiaomi App Market has a code execution vulnerability
    Summary
    A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:22 UTC
    CWE
    • a code execution vulnerability in Xiaomi App Store
    • CWE-95 - Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
    Impacted products
    Vendor Product Version
    Xiaomi App Market Affected: 1.0.0 , ≤ 4.57.4 (custom)
    Create a notification for this product.
    Date Public
    2024-03-14 02:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26323",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:22:30.333129Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-95",
                    "description": "CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code (\u0027Eval Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-02T18:27:06.704Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "App Market",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "4.58.2",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "4.57.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-03-14T02:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Xiaomi App Store APP 4.57.4"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "a code execution vulnerability in Xiaomi App Store",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-20T03:35:34.288Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=543"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Xiaomi App Market has a code execution vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26323",
        "datePublished": "2024-08-28T07:53:42.801Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2026-03-02T18:27:06.704Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-26321 (GCVE-0-2023-26321)

    Vulnerability from cvelistv5 – Published: 2024-08-28 07:51 – Updated: 2025-03-25 15:57
    VLAI
    Title
    The international version of Xiaomi File Manager has a path traversal vulnerability
    Summary
    A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:39 UTC
    CWE
    • A path traversal vulnerability exists
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Xiaomi Xiaomi File Manager App International Version Affected: Xiaomi File Manager App International Version , ≤ V1-210567 (custom)
    Create a notification for this product.
    mi file_manager Affected: 0 , ≤ v1-210586 (custom)
        cpe:2.3:a:mi:file_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-02-08 07:41
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mi:file_manager:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "file_manager",
                "vendor": "mi",
                "versions": [
                  {
                    "lessThanOrEqual": "v1-210586",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26321",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:39:58.176575Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-25T15:57:26.688Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Xiaomi File Manager App International Version",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "V1-210586",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "V1-210567",
                  "status": "affected",
                  "version": "Xiaomi File Manager App International Version",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-02-08T07:41:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Xiaomi File Manager App International Version V1-210567"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "PHYSICAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "A path traversal vulnerability exists",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-28T07:51:28.809Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=541"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "The international version of Xiaomi File Manager has a path traversal vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26321",
        "datePublished": "2024-08-28T07:51:28.809Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2025-03-25T15:57:26.688Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26324 (GCVE-0-2023-26324)

    Vulnerability from cvelistv5 – Published: 2024-08-28 07:28 – Updated: 2024-08-28 13:47
    VLAI
    Title
    GetApps application has code execution vulnerability
    Summary
    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-28 13:46 UTC
    CWE
    • A code execution vulnerability exists
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Xiaomi GetApps application Affected: GetApps application , ≤ 30.6.0.2 (custom)
    Create a notification for this product.
    xiaomi getapps_application Affected: 0 , ≤ 30.6.0.2 (custom)
        cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-05-06 06:01
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "getapps_application",
                "vendor": "xiaomi",
                "versions": [
                  {
                    "lessThanOrEqual": "30.6.0.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26324",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T13:46:06.441446Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T13:47:11.451Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "GetApps application",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "30.6.0.2",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "30.6.0.2",
                  "status": "affected",
                  "version": "GetApps application",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-05-06T06:01:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eA code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "GetApps application 30.6.0.2"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "A code execution vulnerability exists",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-28T07:35:40.482Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://https://trust.mi.com/misrc/bulletins/advisory?cveId=544"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GetApps application has code execution vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26324",
        "datePublished": "2024-08-28T07:28:35.809Z",
        "dateReserved": "2023-02-22T16:59:28.183Z",
        "dateUpdated": "2024-08-28T13:47:11.451Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-27346 (GCVE-0-2023-27346)

    Vulnerability from cvelistv5 – Published: 2024-05-03 01:56 – Updated: 2024-09-18 18:28
    VLAI
    Title
    TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
    Summary
    TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of firmware images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-19703.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-16 19:02 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    TP-Link AX1800 Affected: Archer AX21(US)_V3_1.1.1 Build 20220603
    Create a notification for this product.
    mi ax1800_firmware Affected: 0 , < 3230219 (custom)
        cpe:2.3:o:mi:ax1800_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-03-31 20:45
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:mi:ax1800_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "ax1800_firmware",
                "vendor": "mi",
                "versions": [
                  {
                    "lessThan": "3230219",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-27346",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-16T19:02:06.476318Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-25T15:33:40.656Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T12:09:43.399Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "ZDI-23-377",
                "tags": [
                  "x_research-advisory",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-377/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "AX1800",
              "vendor": "TP-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "Archer AX21(US)_V3_1.1.1 Build 20220603"
                }
              ]
            }
          ],
          "dateAssigned": "2023-02-28T18:05:54.014Z",
          "datePublic": "2023-03-31T20:45:32.764Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the parsing of firmware images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.\n. Was ZDI-CAN-19703."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-18T18:28:03.839Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "name": "ZDI-23-377",
              "tags": [
                "x_research-advisory"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-377/"
            }
          ],
          "source": {
            "lang": "en",
            "value": "Kevin Wang"
          },
          "title": "TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2023-27346",
        "datePublished": "2024-05-03T01:56:05.862Z",
        "dateReserved": "2023-02-28T17:58:45.480Z",
        "dateUpdated": "2024-09-18T18:28:03.839Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26317 (GCVE-0-2023-26317)

    Vulnerability from cvelistv5 – Published: 2023-08-02 00:00 – Updated: 2024-10-16 20:07
    VLAI
    Title
    Xiaomi router external request interface has command injection
    Summary
    Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-16 19:56 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Xiaomi Xiaomi router Affected: Xiaomi Router Firmware version before 2023.2 , ≤ 2023.2 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:23.915Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=529"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26317",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-16T19:56:08.393776Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-16T20:07:44.750Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Xiaomi router",
              "vendor": "Xiaomi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "2023.4",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "2023.2",
                  "status": "affected",
                  "version": "Xiaomi Router Firmware version before 2023.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan style=\"background-color: rgb(245, 247, 249);\"\u003eXiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.\u003c/span\u003e\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-08T09:44:23.934Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=529"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Xiaomi router external request interface has command injection",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26317",
        "datePublished": "2023-08-02T00:00:00.000Z",
        "dateReserved": "2023-02-22T00:00:00.000Z",
        "dateUpdated": "2024-10-16T20:07:44.750Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-26316 (GCVE-0-2023-26316)

    Vulnerability from cvelistv5 – Published: 2023-08-02 00:00 – Updated: 2024-09-27 21:58
    VLAI
    Summary
    A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-27 21:50 UTC
    CWE
    • XSS
    Impacted products
    Vendor Product Version
    n/a Xiaomi cloud service Application Affected: Xiaomi cloud service Application < 1.12.0.0.25
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T11:46:24.361Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=322"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-26316",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-27T21:50:09.403135Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-27T21:58:10.819Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi cloud service Application",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi cloud service Application \u003c 1.12.0.0.25"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview\u0027s whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account\u0027s cookies."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "XSS",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-02T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=322"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2023-26316",
        "datePublished": "2023-08-02T00:00:00.000Z",
        "dateReserved": "2023-02-22T00:00:00.000Z",
        "dateUpdated": "2024-09-27T21:58:10.819Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14140 (GCVE-0-2020-14140)

    Vulnerability from cvelistv5 – Published: 2023-03-29 00:00 – Updated: 2025-02-18 17:10
    VLAI
    Summary
    When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-18 17:09 UTC
    CWE
    • Unauthenticated API that can reveal WIFI password vulnerability
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    n/a Xiaomi Multiple Devices Affected: Xiaomi Multiple Devices, firmware update time in 2020-2022
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.012Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=506"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-14140",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-18T17:09:07.172437Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-306",
                    "description": "CWE-306 Missing Authentication for Critical Function",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-18T17:10:37.810Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi Multiple Devices",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi Multiple Devices, firmware update time in 2020-2022"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Unauthenticated API that can reveal WIFI password vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-03-29T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=506"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14140",
        "datePublished": "2023-03-29T00:00:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2025-02-18T17:10:37.810Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14131 (GCVE-0-2020-14131)

    Vulnerability from cvelistv5 – Published: 2022-10-11 00:00 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.
    Severity
    No CVSS data available.
    CWE
    • a lack of identity verification
    Impacted products
    Vendor Product Version
    n/a Xiaomi specific devices Affected: Xiaomi specific devices,Affected Version:11,Fixed Version:12
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.010Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=153"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi specific devices",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi specific devices,Affected Version:11,Fixed Version:12"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "a lack of identity verification",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-10-11T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=153"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14131",
        "datePublished": "2022-10-11T00:00:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:36.010Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14129 (GCVE-0-2020-14129)

    Vulnerability from cvelistv5 – Published: 2022-10-11 00:00 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.
    Severity
    No CVSS data available.
    CWE
    • Vulnerability logic vulnerability
    Impacted products
    Vendor Product Version
    n/a Xiaomi a certain APP Affected: Affected Version:3.4.5.18 Fixed Version:3.4.5.24
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.494Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=155"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi a certain APP",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Affected Version:3.4.5.18 Fixed Version:3.4.5.24"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Vulnerability logic vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-10-11T00:00:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "url": "https://trust.mi.com/misrc/bulletins/advisory?cveId=155"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14129",
        "datePublished": "2022-10-11T00:00:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:36.494Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14114 (GCVE-0-2020-14114)

    Vulnerability from cvelistv5 – Published: 2022-07-22 15:32 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.
    Severity
    No CVSS data available.
    CWE
    • Information leakage
    References
    Impacted products
    Vendor Product Version
    n/a Xiaomi SmartHome APP Affected: Xiaomi SmartHome APP <=6.4.701
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.202Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Xiaomi SmartHome APP",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Xiaomi SmartHome APP \u003c=6.4.701"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information leakage",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-22T15:32:00.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14114",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Xiaomi SmartHome APP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Xiaomi SmartHome APP \u003c=6.4.701"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information leakage"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=277"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14114",
        "datePublished": "2022-07-22T15:32:00.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:36.202Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14126 (GCVE-0-2020-14126)

    Vulnerability from cvelistv5 – Published: 2022-07-22 15:30 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.
    Severity
    No CVSS data available.
    CWE
    • Information leakage
    References
    Impacted products
    Vendor Product Version
    n/a Mi Sound APP Affected: Mi Sound APP <=2.2.40
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:35.966Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Mi Sound APP",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "Mi Sound APP \u003c=2.2.40"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information leakage",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-22T15:30:39.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14126",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Mi Sound APP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Mi Sound APP \u003c=2.2.40"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information leakage"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=278"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14126",
        "datePublished": "2022-07-22T15:30:39.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:35.966Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14123 (GCVE-0-2020-14123)

    Vulnerability from cvelistv5 – Published: 2022-04-22 15:17 – Updated: 2024-08-04 12:39
    VLAI
    Summary
    There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges.
    Severity
    No CVSS data available.
    CWE
    • Pointer Double Free Vulnerability
    References
    Impacted products
    Vendor Product Version
    n/a MIUI Affected: MIUI version 12.5.2
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:35.902Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MIUI",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "MIUI version 12.5.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Pointer Double Free Vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-22T15:17:36.000Z",
            "orgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
            "shortName": "Xiaomi"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@xiaomi.com",
              "ID": "CVE-2020-14123",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MIUI",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "MIUI version 12.5.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Pointer Double Free Vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134",
                  "refsource": "MISC",
                  "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=134"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b57733aa-7326-4f07-8e09-0be8e0df1909",
        "assignerShortName": "Xiaomi",
        "cveId": "CVE-2020-14123",
        "datePublished": "2022-04-22T15:17:36.000Z",
        "dateReserved": "2020-06-15T00:00:00.000Z",
        "dateUpdated": "2024-08-04T12:39:35.902Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }