CVE-2024-45352

HIGH

Xiaomi smarthome - RCE

Title source: llm
STIX 2.1

Description

An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

Exploits (4)

nomisec WORKING POC 1 stars
by Edwins907 · poc
https://github.com/Edwins907/-CVE-2024-45352
nomisec STUB
by Edwins907 · poc
https://github.com/Edwins907/CVE-2024-45352
nomisec WORKING POC
by Edwins907 · poc
https://github.com/Edwins907/xiaomi-cve-2024-45352

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 5.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-346
Status published
Products (1)
Xiaomi/Xiaomi smarthome application Xiaomi smarthome application 10.0.623
Published Mar 27, 2025
Tracked Since Feb 18, 2026