CVE-2020-14119: Mi AX3600

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12

Affected products

  • Mi AX3600: before 1.1.12 (fixed in 1.1.12)

Published 2021-09-16. Last modified 2026-06-17.