CVE-2020-8994

MEDIUM

XIAOMI AI Speaker MDZ-25-DT Firmware 1.34.36 and 1.40.14 - Unauthenticated Root Shell Access via UART Interface

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-8994. PoCs published by Jian-Xian.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2020-8994, a physical access vulnerability in XIAOMI AI speaker MDZ-25-DT. It demonstrates how attackers can gain root access via UART interface without authentication, leading to various impacts such as reading Wi-Fi credentials, eavesdropping, and system manipulation.

Description

An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then they can read Wi-Fi SSID or password, read the dialogue text files between users and XIAOMI AI speaker, use Text-To-Speech tools pretend XIAOMI speakers' voice achieve social engineering attacks, eavesdrop on users and record what XIAOMI AI speaker hears, delete the entire XIAOMI AI speaker system, modify system files, stop voice assistant service, start the XIAOMI AI speaker’s SSH service as a backdoor

Exploits (1)

github WRITEUP 10 stars
by Jian-Xian · poc
https://github.com/Jian-Xian/CVE-POC/tree/master/CVE-2020-8994.md

This repository provides a detailed technical analysis of CVE-2020-8994, a physical access vulnerability in XIAOMI AI speaker MDZ-25-DT. It demonstrates how attackers can gain root access via UART interface without authentication, leading to various impacts such as reading Wi-Fi credentials, eavesdropping, and system manipulation.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: XIAOMI AI speaker MDZ-25-DT versions 1.34.36, 1.40.14
No auth needed
Prerequisites: physical access to the device · UART connection tools
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (3)

Core 3
Core References
Technical Description, Third Party Advisory x_refsource_misc
https://www.usenix.org/sites/default/files/soups2018posters-lau.pdf
Exploit, Third Party Advisory x_refsource_misc
https://youtu.be/yCadG38yZW8

Scores

CVSS v3 6.8
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
mi/mdz-25-dt_firmware 1.34.36
mi/mdz-25-dt_firmware 1.40.14
Published Mar 05, 2020
Tracked Since Feb 18, 2026