Логотип exploitDog
bind:CVE-2020-14140
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-14140

Количество 2

Количество 2

nvd логотип

CVE-2020-14140

почти 3 года назад

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7h5h-fqwm-4g32

почти 3 года назад

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-14140

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-7h5h-fqwm-4g32

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

CVSS3: 7.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу