CVE-2023-26320 – Xiaomi Router external request interface vulnerability leads to stack overflow
https://notcve.org/view.php?id=CVE-2023-26320
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. La neutralización inadecuada de los elementos especiales utilizados en una vulnerabilidad de comando ("Inyección de comando") en Xiaomi Router permite la inyección de comando. • https://trust.mi.com/misrc/bulletins/advisory?cveId=540 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2023-26319 – Xiaomi Router administration interface vulnerability leads command injection and stack overflow
https://notcve.org/view.php?id=CVE-2023-26319
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. La neutralización inadecuada de los elementos especiales utilizados en una vulnerabilidad de comando ("Inyección de comando") en Xiaomi Router permite la inyección de comando. • https://trust.mi.com/misrc/bulletins/advisory?cveId=536 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2023-26318 – Xiaomi router web interface post-authorization stack overflow
https://notcve.org/view.php?id=CVE-2023-26318
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers. La vulnerabilidad de copia del búfer sin verificar el tamaño de la entrada ('Desbordamiento de búfer clásico') de Xiaomi en Xiaomi Router permite desbordar búferes. • https://trust.mi.com/misrc/bulletins/advisory?cveId=539 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •