CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-45352: Xiaomi smarthome application Webview has code execution vulnerability

8.8 CVSS

Description

An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

Classification

CVE ID: CVE-2024-45352

CVSS Base Severity: HIGH

CVSS Base Score: 8.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem Types

CWE-346 Origin Validation Error

Affected Products

Vendor: Xiaomi

Product: Xiaomi smarthome application

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 3.94% (scored less or equal to compared to others)

EPSS Date: 2025-04-24 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-45352
https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=550

Timeline