Xiaomi CVE 脆弱性と CVE 一覧(101)

製品(CPE): — CVE 件数: 101

Xiaomi 脆弱性概要

Xiaomi 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

過去の問題は主に vendor risk memory corruption and バッファオーバーフロー などに関し、一部は vendor impact memory corruption を招き、vendor surface production workloads and vendor surface software deployment 関連の場面に影響します。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 120 / 101 CVE 件数
«« 先頭 « 前へ 1 / 6 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2024-45348 Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code. [email protected] 6.4 0.31% 2024-09-23 2024-11-25
CVE-2023-26324 A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code. [email protected] 8.8 0.07% 2024-08-28 2024-09-12
CVE-2023-26323 A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code. [email protected] 7.6 0.17% 2024-08-28 2025-03-27
CVE-2023-26322 A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code. [email protected] 8.8 0.15% 2024-08-28 2024-09-12
CVE-2023-26321 A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file. [email protected] 6.3 0.49% 2024-08-28 2025-03-25
CVE-2023-26315 The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device. [email protected] 6.5 67.50% 2024-08-26 2024-10-08
CVE-2024-37664 Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router. [email protected] 5.2 0.07% 2024-06-17 2025-07-09
CVE-2024-37663 Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages. [email protected] 4.1 0.05% 2024-06-17 2025-07-09
CVE-2024-4406 Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the integral-dialog-page.html file. When parsing the integralInfo parameter, the process does not properly sa [email protected] 9.6 70.14% 2024-05-02 2025-08-13
CVE-2024-4405 Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the manual-upgrade.html file. When parsing the manualUpgradeInfo parameter, the process does not properly sanitize [email protected] 9.6 1.79% 2024-05-02 2025-08-13
CVE-2023-26320 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. [email protected] 7.5 1.32% 2023-10-11 2024-11-21
CVE-2023-26319 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. [email protected] 6.7 0.72% 2023-10-11 2024-11-21
CVE-2023-26318 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers. [email protected] 6.7 0.89% 2023-10-11 2024-11-21
CVE-2023-26317 Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing. [email protected] 7.0 0.63% 2023-08-02 2024-11-21
CVE-2023-26316 A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies. [email protected] 6.1 0.46% 2023-08-02 2024-11-21
CVE-2020-14140 When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection. [email protected] 7.5 1.42% 2023-03-29 2025-02-18
CVE-2020-14131 The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life. [email protected] 9.8 0.50% 2022-10-11 2024-11-21
CVE-2020-14129 A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege. [email protected] 9.8 0.50% 2022-10-11 2024-11-21
CVE-2020-14126 Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information. [email protected] 7.5 0.32% 2022-07-22 2024-11-21
CVE-2020-14114 information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information. [email protected] 7.5 0.32% 2022-07-22 2024-11-21
«« 先頭 « 前へ 1 / 6 次へ »
cvelogic Threat Intelligence