CVE-2019-20481: Miele Xgw 3000 Zigbee Gateway Firmware
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
Affected products
- Miele Xgw 3000 Zigbee Gateway Firmware: before 2.4.0 (fixed in 2.4.0)
Published 2020-02-24. Last modified 2026-06-17.