CVE-2024-37664

MEDIUM

Redmi AX6S Firmware - TCP Denial of Service or Traffic Hijacking via Forged RST Messages

Title source: llm
STIX 2.1

Description

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

Scores

CVSS v3 5.2
EPSS 0.0037
EPSS Percentile 29.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-940
Status published
Products (1)
mi/redmi_ax6s_firmware 1.0.57
Published Jun 17, 2024
Tracked Since Feb 18, 2026