Xiaomi MDZ-25-DT Firmware 1.40.14

CPE Details

Xiaomi MDZ-25-DT Firmware 1.40.14
1.40.14
2020-04-02
14h01 +00:00
2020-04-02
14h01 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:mi:mdz-25-dt_firmware:1.40.14:*:*:*:*:*:*:*

Informations

Vendor

mi

Product

mdz-25-dt_firmware

Version

1.40.14

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-8994 2020-03-05
14h43 +00:00
An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then they can read Wi-Fi SSID or password, read the dialogue text files between users and XIAOMI AI speaker, use Text-To-Speech tools pretend XIAOMI speakers' voice achieve social engineering attacks, eavesdrop on users and record what XIAOMI AI speaker hears, delete the entire XIAOMI AI speaker system, modify system files, stop voice assistant service, start the XIAOMI AI speaker’s SSH service as a backdoor
6.8
Medium