When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-6299 | When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Xiaomi
Published:
Updated: 2025-02-18T17:10:37.810Z
Reserved: 2020-06-15T00:00:00.000Z
Link: CVE-2020-14140

Updated: 2024-08-04T12:39:36.012Z

Status : Modified
Published: 2023-03-29T20:15:07.087
Modified: 2025-02-18T18:15:09.703
Link: CVE-2020-14140

No data.

No data.