Home Cyber Security News Xiaomi Interoperability App Flaw Allows Hackers Unauthorized Device Access

Xiaomi Interoperability App Flaw Allows Hackers Unauthorized Device Access

0

A serious security flaw (CVE-2024-45347) in Xiaomi’s interoperability application allows attackers to bypass authentication protocols and gain unrestricted access to user devices.

The vulnerability, rated CVSS 9.6 (Critical), stems from flawed validation logic in the app’s security mechanisms.

Affected versions include Xiaomi Interconnection Application 3.1.895.10 and earlier, with a patched version 3.1.921.10 now available.

Technical Breakdown of the Exploit

The vulnerability resides in the authentication protocol handling of the Xiaomi Mi Connect Service APP.

Attackers exploit improper validation checks to bypass security measures, enabling unauthorized command execution and device access.

This flaw allows:

  • Remote execution of arbitrary code without user interaction
  • Compromise of sensitive device functions and data
  • Full control over affected devices when leveraged with other attack vectors

Affected Systems and Mitigation

ComponentAffected VersionPatched Version
Xiaomi Interconnection Application≤3.1.895.103.1.921.10

Xiaomi confirmed the immediate availability of the fixed version through automatic updates. Users must verify their app version and install updates promptly.

The company’s security team acknowledged researcher Liu Xiaofeng from Shandong University for responsible disclosure.

Broader Security Implications

This incident highlights persistent security challenges in IoT interoperability frameworks.

Xiaomi’s advisory confirms ongoing collaboration with external researchers through their Mi Security Center (MiSRC) program to address vulnerabilities.

The company emphasizes:

  • Implementation of enhanced input validation protocols
  • Rigorous security audits of authentication pathways
  • Continuous monitoring for similar flaws in interconnected services

The vulnerability underscores critical infrastructure risks in smart device ecosystems, where a single compromised component can expose entire networks.

Xiaomi urges all users to implement updates immediately and maintain vigilance against suspicious access requests.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version