CVE-2024-37663: Mi Redmi AX6S Firmware

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

Affected products

  • Mi Redmi AX6S Firmware: version 1.0.57 only

Published 2024-06-17. Last modified 2026-06-17.