890
VMScore

CVE-2018-14060

Published: 15/07/2018 Updated: 12/09/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D prior to 2.26.4 devices allows an malicious user to execute any command via crafted JSON data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mi xiaomi_r3d_firmware

Github Repositories

router CVE-2018-14010 CVE-2018-14060