When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Xiaomi
Published: 2023-03-29T00:00:00
Updated: 2024-08-04T12:39:36.012Z
Reserved: 2020-06-15T00:00:00
Link: CVE-2020-14140
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-29T20:15:07.087
Modified: 2024-11-21T05:02:43.803
Link: CVE-2020-14140
Redhat
No data.