CVE Tools

Mi

64 CVEs tracked since 2018. Since Dec 2018, none of them reached CISA KEV.

Mi CVEs per month

Dec 2018 to Aug 2024. Point at a month, or focus the strip and use the arrow keys.
Mi CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-1220
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-1020
2019-11150
2019-1230
2020-01null or fewer
2020-0220
2020-0330
2020-04null or fewer
2020-05null or fewer
2020-0660
2020-07null or fewer
2020-08null or fewer
2020-0920
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-0140
2021-02null or fewer
2021-03null or fewer
2021-0450
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-0950
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-0470
2022-05null or fewer
2022-06null or fewer
2022-0730
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-0850

Products

The products that kept showing up in Mi's monthly top three, with their CVEs summed over those months.

  1. Miui73 months
  2. Xiaomi R3600 Firmware51 month
  3. AX1800 Firmware42 months
  4. RM1800 Firmware42 months
  5. A2 Lite Firmware31 month
  6. Mccgq01lm Firmware31 month
  7. Rtcgq01lm Firmware31 month
  8. ZNCZ03LM Firmware31 month
  9. AX3600 Firmware21 month
  10. Getapps21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Mi.

  1. CVE-2024-45348Xiaomi Router AX9000 has a post-authorization command injection vulnerability6.4
  2. CVE-2023-26322GetApps application has code execution vulnerability8.8
  3. CVE-2023-26323Xiaomi App Market has a code execution vulnerability7.6
  4. CVE-2023-26321The international version of Xiaomi File Manager has a path traversal vulnerability6.3
  5. CVE-2023-26324GetApps application has code execution vulnerability8.8
  6. CVE-2023-26315Xiaomi router has a command injection vulnerability after authorization6.5
  7. CVE-2024-37664Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by ...5.2
  8. CVE-2024-37663Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sendin...4.1
  9. CVE-2024-4406Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability9.6
  10. CVE-2024-4405Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability9.6
  11. CVE-2023-26320Xiaomi Router external request interface vulnerability leads to stack overflow7.5
  12. CVE-2023-26319Xiaomi Router administration interface vulnerability leads command injection and stack overflow6.7
  13. CVE-2023-26318Xiaomi router web interface post-authorization stack overflow6.7
  14. CVE-2023-26316A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be...6.1
  15. CVE-2023-26317Xiaomi router external request interface has command injection7.0

The record

Peak rank
#38 in Nov 2019
Busiest month shown
Nov 2019, 15 CVEs
Months with a KEV entry
0 since Dec 2018
Monthly snapshots
14 since 2018
Mi's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store