CVE-2020-14140

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
29/03/2023
Last modified:
18/02/2025

Description

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mi:xiaomi_router_firmware:*:*:*:*:*:*:*:* 2020 (including) 2023.2 (excluding)