CVE-2020-14096: Mi Xiaomi Ai Speaker Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.

Affected products

  • Mi Xiaomi Ai Speaker Firmware: before 1.59.6 (fixed in 1.59.6)

Published 2020-09-11. Last modified 2026-06-17.