Xiaomi Technology Co., Ltd.
Self-Reporting Analysis
Of all the CVEs published by Xiaomi Technology Co., Ltd. as a CNA, 0.0% affect products that Xiaomi Technology Co., Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Xiaomi Technology Co., Ltd., 0.0% are self-published by Xiaomi Technology Co., Ltd. as a CNA.
Trends Over Time
The number and severity of CVEs published by Xiaomi Technology Co., Ltd. over time
Top CVEs
All CVEs published by Xiaomi Technology Co., Ltd. as a CNA, regardless of affected vendor or product.
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26315HIGH The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it | Aug 26, 2024 | 8.8 | 35 | NO | NO |
CVE-2020-14100CRITICAL In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this | Sep 11, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-14095CRITICAL In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code executio | Jun 24, 2020 | 9.8 | 31 | NO | NO |
CVE-2023-26317CRITICAL Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can expl | Aug 2, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-14115CRITICAL A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vu | Mar 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-14124CRITICAL There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12. | Sep 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-14119CRITICAL There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom | Sep 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-26322CRITICAL A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit t | Aug 28, 2024 | 9.8 | 29 | NO | NO |
CVE-2020-14131CRITICAL The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security team | Oct 11, 2022 | 9.8 | 29 | NO | NO |
CVE-2024-45347CRITICAL An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to | Jun 23, 2025 | 9.6 | 28 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (56 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Xiaomi Technology Co., Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Xiaomi Technology Co., Ltd. as a CNA — matched by CVE ID, not by organization name.