CRITICAL🇵🇱 Wersja polska

CVE-2024-4405

CVSS 9.6v3.1pub. 2024-05-02upd. 2025-08-13

Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the manual-upgrade.html file. When parsing the manualUpgradeInfo parameter, the process does not properly sanitize user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22379.

🤖 AI Analysis
How it works

The vulnerability exists in the manual-upgrade.html file, which is responsible for manual updates in the Mi Market application. The manualUpgradeInfo parameter is not properly sanitized — the application does not filter user-supplied data, allowing arbitrary script injection. The attacker must trick the victim into visiting a malicious website or opening a malicious file, and can then execute code in the context of the current device user.

Impact

An attacker can execute arbitrary code in the context of a logged-in user, potentially gaining full control over the device's data and functions. Confidentiality, data integrity, and system availability are at risk.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is recommended to monitor Xiaomi 13 Pro firmware updates and install patches immediately after their release. Until the vulnerability is patched, exercise particular caution when opening unknown files and visiting untrusted websites.

Who is affected

Xiaomi 13 Pro and Xiaomi 13 Pro Firmware — specific versions indicated in the manufacturer's references and ZDI-24-418 advisory

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Mi Xiaomi 13 Pro

    HW
    Mi
    all versions
  • Mi Xiaomi 13 Pro Firmware

    OS
    Mi
    14.0.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2024-4406CRITICAL9.6PL ✓same product

XSS umożliwiający RCE w aplikacji GetApps na Xiaomi 13 Pro

CVE-2020-14131CRITICAL9.8PL ✓same vendor

Krytyczna podatność w urządzeniach Xiaomi Mi (CVE-2020-14131)

CVE-2020-14129CRITICAL9.8PL ✓same vendor

Błąd logiczny w produkcie Xiaomi — nieprawidłowa weryfikacja tożsamości

CVE-2020-14115CRITICAL9.8PL ✓same vendor

Command injection w routerze Xiaomi AX3600 — zdalne wykonanie kodu

CVE-2020-14119CRITICAL9.8PL ✓same vendor

Command injection w interfejsie addMeshNode routera Xiaomi AX3600