CVE-2020-14140

HIGH

Xiaomi Router Firmware 2020-2023.2 - Unauthenticated WIFI Password Exposure via API

Title source: llm
STIX 2.1

Description

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0103
EPSS Percentile 59.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
mi/xiaomi_router_firmware 2020 - 2023.2
Published Mar 29, 2023
Tracked Since Feb 18, 2026