When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
History

Tue, 18 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xiaomi

Published:

Updated: 2025-02-18T17:10:37.810Z

Reserved: 2020-06-15T00:00:00.000Z

Link: CVE-2020-14140

cve-icon Vulnrichment

Updated: 2024-08-04T12:39:36.012Z

cve-icon NVD

Status : Modified

Published: 2023-03-29T20:15:07.087

Modified: 2025-02-18T18:15:09.703

Link: CVE-2020-14140

cve-icon Redhat

No data.