CVE-2020-14100: Mi r3600 Firmware

Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.

In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.

Affected products

  • Mi r3600 Firmware: before 1.0.66 (fixed in 1.0.66)

Published 2020-09-11. Last modified 2026-06-17.