Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the manual-upgrade.html file. When parsing the manualUpgradeInfo parameter, the process does not properly sanitize user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22379.
The vulnerability exists in the manual-upgrade.html file, which is responsible for manual updates in the Mi Market application. The manualUpgradeInfo parameter is not properly sanitized — the application does not filter user-supplied data, allowing arbitrary script injection. The attacker must trick the victim into visiting a malicious website or opening a malicious file, and can then execute code in the context of the current device user.
An attacker can execute arbitrary code in the context of a logged-in user, potentially gaining full control over the device's data and functions. Confidentiality, data integrity, and system availability are at risk.
Apply patches available from the manufacturer according to the references. It is recommended to monitor Xiaomi 13 Pro firmware updates and install patches immediately after their release. Until the vulnerability is patched, exercise particular caution when opening unknown files and visiting untrusted websites.
Xiaomi 13 Pro and Xiaomi 13 Pro Firmware — specific versions indicated in the manufacturer's references and ZDI-24-418 advisory
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HMi Xiaomi 13 Pro
HWMiall versionsMi Xiaomi 13 Pro Firmware
OSMi14.0.5.0
Related vulnerabilities
XSS umożliwiający RCE w aplikacji GetApps na Xiaomi 13 Pro
Krytyczna podatność w urządzeniach Xiaomi Mi (CVE-2020-14131)
Błąd logiczny w produkcie Xiaomi — nieprawidłowa weryfikacja tożsamości
Command injection w routerze Xiaomi AX3600 — zdalne wykonanie kodu
Command injection w interfejsie addMeshNode routera Xiaomi AX3600