CVE-2023-26315: Mi AX9000 Firmware

High severity, CVSS 8.8. EPSS: 19.4% chance of exploitation in the next 30 days.

The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.

Affected products

  • Mi AX9000 Firmware: from 1.0.0, before 1.0.174 (fixed in 1.0.174)

Published 2024-08-26. Last modified 2026-06-17.