CVE-2020-14102

HIGH

Xiaomi AX1800 and RM1800 Firmware < 1.0.336 and < 1.0.26 - Command Injection via DDNS Hostname Processing

Title source: llm
STIX 2.1

Description

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

Scores

CVSS v3 7.2
EPSS 0.0188
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (2)
mi/ax1800_firmware < 1.0.336
mi/rm1800_firmware < 1.0.26
Published Jan 13, 2021
Tracked Since Feb 18, 2026