There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12 Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14119 Reference (s):
- https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=16
- URL: https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=16

