CVE-2024-37664

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mi:redmi_ax6s_firmware:1.0.57:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_ax6s:-:*:*:*:*:*:*:*

History

09 Jul 2025, 15:05

Type Values Removed Values Added
References () https://github.com/ouuan/router-vuln-report/blob/master/nat-rst/redmi-rb03-nat-rst.md - () https://github.com/ouuan/router-vuln-report/blob/master/nat-rst/redmi-rb03-nat-rst.md - Exploit, Third Party Advisory
CPE cpe:2.3:h:mi:redmi_ax6s:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_ax6s_firmware:1.0.57:*:*:*:*:*:*:*
First Time Mi
Mi redmi Ax6s Firmware
Mi redmi Ax6s

Information

Published : 2024-06-17 18:15

Updated : 2025-07-09 15:05


NVD link : CVE-2024-37664

Mitre link : CVE-2024-37664

CVE.ORG link : CVE-2024-37664


JSON object : View

Products Affected

mi

  • redmi_ax6s
  • redmi_ax6s_firmware
CWE
CWE-940

Improper Verification of Source of a Communication Channel