CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2020-14131

CVSS 9.8v3.1pub. 2022-10-11upd. 2024-11-21

The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mi Xiaomi

    APP
    Mi
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2020-14129CRITICAL9.8PL ✓same product

Błąd logiczny w produkcie Xiaomi — nieprawidłowa weryfikacja tożsamości

CVE-2020-14130MEDIUM5.3same product

Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called ...

CVE-2024-4406CRITICAL9.6PL ✓same vendor

XSS umożliwiający RCE w aplikacji GetApps na Xiaomi 13 Pro

CVE-2024-4405CRITICAL9.6PL ✓same vendor

XSS umożliwiający RCE w Xiaomi 13 Pro — plik manual-upgrade.html

CVE-2020-14115CRITICAL9.8PL ✓same vendor

Command injection w routerze Xiaomi AX3600 — zdalne wykonanie kodu