A critical vulnerability in Xiaomiβs Mi Connect Service App, identified as CVE-2024-45347, allows remote attackers on the same network to control smart devices without user permission. Users are urged to update to the patched version 3.1.921.10 and implement security measures to prevent exploitation. #CVE-2024-45347 #XiaomiMiConnect
Keypoints
- The vulnerability stems from improper authentication in the Mi Connect Service App.
- Attackers can exploit the flaw without user interaction if they are on the same network segment.
- The flaw allows unauthorized access, modification of device settings, and potential device disruption.
- Xiaomi has released a security patch in version 3.1.921.10 to address this critical issue.
- Security experts recommend updating the app, restricting network access, and monitoring for suspicious activity.
Read More: https://gbhackers.com/xiaomi-interoperability-app-flaw/