10
CVSSv2

CVE-2018-14010

Published: 15/07/2018 Updated: 12/09/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P prior to 2.14.5, R3C prior to 2.12.15, R3 prior to 2.22.15, and R3D prior to 2.26.4 devices allows an malicious user to execute any command via crafted JSON data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mi xiaomi_r3p_firmware

mi xiaomi_r3c_firmware

mi xiaomi_r3d_firmware

mi xiaomi_r3

Github Repositories

router CVE-2018-14010 CVE-2018-14060