Mi's vulnerability footprint encompasses a moderately represented portfolio of networking and smart home devices, particularly routers and their associated firmware, along with the MIUI operating system, positioning these products across consumer and enterprise network edges. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes spanning command and OS command injection, out-of-bounds writes, and improper resource reference handling—patterns characteristic of firmware-level code and system integration layers. The exposure concentrates in router products such as the AX3600 series and their firmware implementations, where these command-injection and memory-safety flaws present direct paths to device compromise and lateral network movement. Defenders should inventory Mi-branded networking devices and prioritize firmware updates for internet-facing router models; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mi over time
Signals from CVEs in this vendor scope (101 CVEs).
101 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6065HIGH Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to pot | Nov 14, 2018 | 8.8 | 93 | YES | YES |
CVE-2019-18371HIGH An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, a | Oct 23, 2019 | 7.5 | 67 | NO | YES |
CVE-2019-18370CRITICAL An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decom | Oct 23, 2019 | 9.8 | 53 | NO | NO |
CVE-2018-16130HIGH System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter. | Nov 27, 2018 | 8.8 | 38 | NO | NO |
CVE-2018-13023HIGH System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter. | Nov 27, 2018 | 8.8 | 38 | NO | NO |
CVE-2023-26315HIGH The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it | Aug 26, 2024 | 8.8 | 35 | NO | NO |
CVE-2020-14100CRITICAL In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this | Sep 11, 2020 | 9.8 | 32 | NO | NO |
CVE-2018-20523MEDIUM Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can rea | Jun 7, 2019 | 5.3 | 32 | NO | YES |
CVE-2020-10561CRITICAL An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulne | Jun 24, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-14095CRITICAL In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code executio | Jun 24, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (101 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mi.
Media articles that mention a CVE ID that affects a product developed by Mi — matched by CVE ID, not by vendor name.