Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authentication
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://privacy.mi.com/trust#/security/vulnerability-management/vulnerability-announcement/detail?id=16 | vendor advisory |