CVE-2024-45348: Mi AX9000 Firmware

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.

Affected products

  • Mi AX9000 Firmware: before 1.0.174 (fixed in 1.0.174)

Published 2024-09-23. Last modified 2026-06-17.