CVE-2024-45347: Xiaomi Mi Connect Service

Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.

An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.

Affected products

  • Xiaomi Xiaomi Mi Connect Service

Published 2025-06-23. Last modified 2026-06-17.