Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mi

First CVE: Jul 15, 2018Active for: 8 yearsTotal CVEs: 101
51.9
VTI Score
TOP TARGET

Mi's vulnerability footprint encompasses a moderately represented portfolio of networking and smart home devices, particularly routers and their associated firmware, along with the MIUI operating system, positioning these products across consumer and enterprise network edges. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes spanning command and OS command injection, out-of-bounds writes, and improper resource reference handling—patterns characteristic of firmware-level code and system integration layers. The exposure concentrates in router products such as the AX3600 series and their firmware implementations, where these command-injection and memory-safety flaws present direct paths to device compromise and lateral network movement. Defenders should inventory Mi-branded networking devices and prioritize firmware updates for internet-facing router models; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
101
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
1.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Mi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2018
8 years ago
Most Recent CVE
Sep 23, 2024
669 days ago

Products(148 total)

Top CVEs

Signals from CVEs in this vendor scope (101 CVEs).

101 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-6065HIGH
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to pot
Nov 14, 20188.893YESYES
CVE-2019-18371HIGH
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, a
Oct 23, 20197.567NOYES
CVE-2019-18370CRITICAL
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decom
Oct 23, 20199.853NONO
CVE-2018-16130HIGH
System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter.
Nov 27, 20188.838NONO
CVE-2018-13023HIGH
System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter.
Nov 27, 20188.838NONO
CVE-2023-26315HIGH
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it
Aug 26, 20248.835NONO
CVE-2020-14100CRITICAL
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this
Sep 11, 20209.832NONO
CVE-2018-20523MEDIUM
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can rea
Jun 7, 20195.332NOYES
CVE-2020-10561CRITICAL
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulne
Jun 24, 20209.831NONO
CVE-2020-14095CRITICAL
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code executio
Jun 24, 20209.831NONO
View all 101 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products101 CVEs
31%
40%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local23 (22.8%)
Network67 (66.3%)
Unknown0 (0.0%)
Physical4 (4.0%)
Adjacent Network7 (6.9%)
Attack Complexity
Low97 (96.0%)
High4 (4.0%)
Unknown0 (0.0%)
User Interaction
None84 (83.2%)
Unknown0 (0.0%)
Required17 (16.8%)
Privileges Required
Low27 (26.7%)
High4 (4.0%)
None70 (69.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (101 CVEs).

CISA KEV
1 CVE
1.0% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.0% of CVEs· 95th percentile
ExploitDB
2 CVEs
2.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mi's Products

View all 4 CNAs →

Top CWEs