A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.
References
| Link | Resource |
|---|---|
| https://github.com/pastcompute/tichome-poc-1 | Exploit Third Party Advisory |
| https://web.archive.org/web/20171202094530/ | Not Applicable |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-03-04 16:16
Updated : 2026-03-05 18:13
NVD link : CVE-2026-26478
Mitre link : CVE-2026-26478
CVE.ORG link : CVE-2026-26478
JSON object : View
Products Affected
mobvoi
- tichome_mini_firmware
- tichome_mini
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
