Vulnerabilities > MI > Low

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2020-14122 Insufficient Verification of Data Authenticity vulnerability in MI Miui 12.5.2
Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user information leakage.
local
low complexity
mi CWE-345
2.1
2022-04-21 CVE-2020-14121 Incorrect Authorization vulnerability in MI APP Store 4.12.2
A business logic vulnerability exists in Mi App Store.
local
low complexity
mi CWE-863
2.1
2021-04-20 CVE-2020-14105 Unspecified vulnerability in MI Miui
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
local
low complexity
mi
2.1
2019-11-14 CVE-2019-15340 Incorrect Permission Assignment for Critical Resource vulnerability in MI Redmi 6 Firmware
The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006) that allows any app co-located on the device to programmatically disable and enable Wi-Fi, Bluetooth, and GPS without the corresponding access permission through an exported interface.
local
low complexity
mi CWE-732
2.1
2019-11-14 CVE-2019-15415 Externally Controlled Reference to a Resource in Another Sphere vulnerability in MI Redmi 5 Firmware
The Xiaomi Redmi 5 Android device with a build fingerprint of xiaomi/vince/vince:7.1.2/N2G47H/V9.5.4.0.NEGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1711_201803291645) that allows unauthorized wireless settings modification via a confused deputy attack.
local
low complexity
mi CWE-610
2.1
2019-11-14 CVE-2019-15426 Externally Controlled Reference to a Resource in Another Sphere vulnerability in MI 5S Plus Firmware
The Xiaomi 5S Plus Android device with a build fingerprint of Xiaomi/natrium/natrium:6.0.1/MXB48T/7.1.5:user/release-keys contains a pre-installed app with a package name of com.miui.powerkeeper app (versionCode=40000, versionName=4.0.00) that allows unauthorized wireless settings modification via a confused deputy attack.
local
low complexity
mi CWE-610
2.1
2019-11-14 CVE-2019-15427 Externally Controlled Reference to a Resource in Another Sphere vulnerability in MI MIX Firmware
The Xiaomi Mi Mix Android device with a build fingerprint of Xiaomi/lithium/lithium:6.0.1/MXB48T/7.1.5:user/release-keys contains a pre-installed app with a package name of com.miui.powerkeeper app (versionCode=40000, versionName=4.0.00) that allows unauthorized wireless settings modification via a confused deputy attack.
local
low complexity
mi CWE-610
2.1
2019-11-14 CVE-2019-15428 Externally Controlled Reference to a Resource in Another Sphere vulnerability in MI Note 2 Firmware
The Xiaomi Mi Note 2 Android device with a build fingerprint of Xiaomi/scorpio/scorpio:6.0.1/MXB48T/7.1.5:user/release-keys contains a pre-installed app with a package name of com.miui.powerkeeper app (versionCode=40000, versionName=4.0.00) that allows unauthorized wireless settings modification via a confused deputy attack.
local
low complexity
mi CWE-610
2.1
2019-11-14 CVE-2019-15466 Externally Controlled Reference to a Resource in Another Sphere vulnerability in MI Redmi 6 PRO Firmware
The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V10.2.6.0.ODMMIXM:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201812191721) that allows unauthorized wireless settings modification via a confused deputy attack.
local
low complexity
mi CWE-610
2.1
2019-11-14 CVE-2019-15467 Externally Controlled Reference to a Resource in Another Sphere vulnerability in MI MIX 2S Firmware
The Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=A2060_201801032053) that allows unauthorized wireless settings modification via a confused deputy attack.
local
low complexity
mi CWE-610
2.1