Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) read Wi-Fi SSID or password, (ii) read the dialogue text files between users and XIAOMI XIAOAI speaker Pro LX06, (iii) use Text-To-Speech tools pretend XIAOMI speakers' voice achieve social engineering attacks, (iv) eavesdrop on users and record what XIAOMI XIAOAI speaker Pro LX06 hears, (v) modify system files, (vi) use commands to send any IR code through IR emitter on XIAOMI XIAOAI Speaker Pro LX06, (vii) stop voice assistant service, (viii) enable the XIAOMI XIAOAI Speaker Pro’ SSH or TELNET service as a backdoor, (IX) tamper with the router configuration of the router in the local area networks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xiaomi Xiao AI Speaker Pro LX06 输入验证错误漏洞
Vulnerability Description
Xiaomi Xiao AI Speaker Pro LX06是中国小米科技(Xiaomi)公司的一款智能音箱。 Xiaomi Xiao AI Speaker Pro LX06 1.52.4版本中存在输入验证错误漏洞。攻击者可通过访问UART接口利用该漏洞获取root shell,进而读取Wi-Fi SSID或密码,停止语音助手服务,修改局域网内路由器配置,修改系统文件或执行其他恶意操作。
CVSS Information
N/A
Vulnerability Type
N/A