There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12
No PoCs from references.
- https://github.com/attilaszia/linux-iot-cves