System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter.
2018-11-27T20:29:00.800
2024-11-21T03:52:07.477
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | mi | miwifi_os | 2.22.15 | Yes |
Hardware | mi | mi_router_3 | - | No |