NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。
Assigner(CNA/発行元):[email protected] この条件を外す
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2023-26315 | The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device. | 6.5 | 19.39% | 2024-08-26 | 2026-06-17 |
| CVE-2020-14125 | A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited by attackers to make denial of service. | 7.5 | 6.93% | 2022-06-08 | 2026-06-16 |
| CVE-2020-14100 | In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability. | 9.8 | 5.18% | 2020-09-11 | 2026-06-16 |
| CVE-2020-14119 | There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12 | 9.8 | 2.96% | 2021-09-16 | 2026-06-16 |
| CVE-2020-14095 | In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code execution. | 9.8 | 2.33% | 2020-06-24 | 2026-06-16 |
| CVE-2020-14094 | In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution. | 9.8 | 2.33% | 2020-06-24 | 2026-06-16 |
| CVE-2020-14109 | There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12 | 7.2 | 2.17% | 2021-09-16 | 2026-06-16 |
| CVE-2020-14124 | There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12. | 9.8 | 1.95% | 2021-09-16 | 2026-06-16 |
| CVE-2020-14102 | There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26. | 7.2 | 1.88% | 2021-01-13 | 2026-06-16 |
| CVE-2020-14098 | The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26. | 7.5 | 1.22% | 2021-01-13 | 2026-06-16 |
| CVE-2020-14096 | Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process. | 9.8 | 1.21% | 2020-09-11 | 2026-06-16 |
| CVE-2020-14115 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. | 9.8 | 1.08% | 2022-03-10 | 2026-06-16 |
| CVE-2020-14101 | The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26. | 7.5 | 1.06% | 2021-01-13 | 2026-06-16 |
| CVE-2020-14140 | When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection. | 7.5 | 1.03% | 2023-03-29 | 2026-06-16 |
| CVE-2020-14127 | A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attackers to make remote denial of service. | 7.5 | 0.98% | 2022-07-14 | 2026-06-16 |
| CVE-2023-26320 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. | 7.5 | 0.97% | 2023-10-11 | 2026-06-17 |
| CVE-2020-14107 | A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN. | 7.5 | 0.96% | 2022-01-18 | 2026-06-16 |
| CVE-2023-26317 | Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing. | 7.0 | 0.95% | 2023-08-02 | 2026-06-17 |
| CVE-2020-14129 | A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege. | 9.8 | 0.91% | 2022-10-11 | 2026-06-16 |
| CVE-2023-26319 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. | 6.7 | 0.88% | 2023-10-11 | 2026-06-17 |