CVE-2020-11960 describes a critical vulnerability in Xiaomi Router R3600 ROM versions prior to 1.0.50, where a flaw in the c_upload interface's backup file check allows unauthenticated attackers to extract malicious files to arbitrary /tmp locations. This can lead to remote code execution (RCE) and denial of service (DoS) with a CVSS score of 9.8. Despite its high severity and ease of exploitation (network attack, low complexity, no user interaction), there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.20CPE matchmatch criteria | cpe:2.3:o:mi:xiaomi_r3600_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.