Xiaomi Technology Co., Ltd.

First CVE: Jun 24, 2020Active for: 6 years
56
CVEs Published
More CVEs Published than 60% of tracked CNAs
9.3
Avg CVEs / Year
More Avg CVEs / Year than 51% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Xiaomi Technology Co., Ltd. as a CNA, 0.0% affect products that Xiaomi Technology Co., Ltd. develops as a vendor.

100.0%
Self-reported: 0Third-party: 56

Of all the CVEs published that affect products developed by Xiaomi Technology Co., Ltd., 0.0% are self-published by Xiaomi Technology Co., Ltd. as a CNA.

100.0%
Self-published: 0Published by other CNAs: 2

Trends Over Time

The number and severity of CVEs published by Xiaomi Technology Co., Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2020
6 years ago
Most Recent CVE
Jun 23, 2025
396 days ago

Top CVEs

All CVEs published by Xiaomi Technology Co., Ltd. as a CNA, regardless of affected vendor or product.

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it
Aug 26, 20248.835NONO
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this
Sep 11, 20209.832NONO
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code executio
Jun 24, 20209.831NONO
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can expl
Aug 2, 20239.830NONO
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vu
Mar 10, 20229.830NONO
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
Sep 16, 20219.830NONO
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom
Sep 16, 20219.830NONO
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit t
Aug 28, 20249.829NONO
The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security team
Oct 11, 20229.829NONO
An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to
Jun 23, 20259.628NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA56 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local10 (17.9%)
Network44 (78.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.6%)
Attack Complexity
Low54 (96.4%)
High2 (3.6%)
Unknown0 (0.0%)
User Interaction
None44 (78.6%)
Unknown0 (0.0%)
Required12 (21.4%)
Privileges Required
Low7 (12.5%)
High4 (7.1%)
None45 (80.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (56 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Xiaomi Technology Co., Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Xiaomi Technology Co., Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs