A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mobvoi Tichome_Mini_Firmware
cpe:2.3:o:mobvoi:tichome_mini_firmware:012-18853:*:*:*:*:*:*:*
|
— | — |
|
Mobvoi Tichome_Mini_Firmware
cpe:2.3:o:mobvoi:tichome_mini_firmware:027-58389:*:*:*:*:*:*:*
|
— | — |
|
Mobvoi Tichome_Mini
cpe:2.3:h:mobvoi:tichome_mini:-:*:*:*:*:*:*:*
|
— | — |