The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.51954}

epss

{'score': 0.46723}


Mon, 14 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.50316}

epss

{'score': 0.51954}


Tue, 08 Oct 2024 19:00:00 +0900

Type Values Removed Values Added
Weaknesses CWE-78

Sat, 07 Sep 2024 07:45:00 +0900

Type Values Removed Values Added
First Time appeared Mi
Mi ax9000
Mi ax9000 Firmware
Weaknesses CWE-77
CPEs cpe:2.3:h:mi:ax9000:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:ax9000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Mi
Mi ax9000
Mi ax9000 Firmware

Tue, 27 Aug 2024 03:30:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 21:00:00 +0900

Type Values Removed Values Added
Description The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
Title Xiaomi router has a command injection vulnerability after authorization
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Xiaomi

Published:

Updated: 2024-10-08T09:49:35.915Z

Reserved: 2023-02-22T16:59:28.182Z

Link: CVE-2023-26315

cve-icon Vulnrichment

Updated: 2024-08-26T17:40:07.193Z

cve-icon NVD

Status : Modified

Published: 2024-08-26T12:15:05.387

Modified: 2024-10-08T10:15:03.300

Link: CVE-2023-26315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses