CVE-2020-14140
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
29/03/2023
Last modified:
18/02/2025
Description
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mi:xiaomi_router_firmware:*:*:*:*:*:*:*:* | 2020 (including) | 2023.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



