There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
2021-01-13T23:15:13.260
2024-11-21T05:02:39.053
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | mi | ax1800_firmware | < 1.0.336 | Yes |
Hardware | mi | ax1800 | - | No |
Operating System | mi | rm1800_firmware | < 1.0.26 | Yes |
Hardware | mi | rm1800 | - | No |