CVE detail
CVE-2020-14140 — CVE-2020-14140
Published 2023-03-29 · Modified 2026-06-17 · Vendor mi · Product xiaomi_router_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0099
EPSS probability
exploitation probability, 30d
59.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References