CVE-2023-26315: Mi AX9000 Firmware
High severity, CVSS 8.8. EPSS: 19.4% chance of exploitation in the next 30 days.
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
Affected products
- Mi AX9000 Firmware: from 1.0.0, before 1.0.174 (fixed in 1.0.174)
Published 2024-08-26. Last modified 2026-06-17.