CVE-2020-14098: Mi AX1800 Firmware
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
Affected products
- Mi AX1800 Firmware: before 1.0.336 (fixed in 1.0.336)
- Mi RM1800 Firmware: before 1.0.26 (fixed in 1.0.26)
Published 2021-01-13. Last modified 2026-06-17.