What is CVE-2026-72580?
An OS command injection vulnerability in duhow/xiaoai-patch allows remote attackers to execute arbitrary system commands on Xiaomi smart speakers. The flaw exists in the /mute and /unmute endpoints where user-supplied 'silent' parameter is improperly handled. Affected systems should be patched or isolated immediately.
Azərbaycanca: Bu, duhow/xiaoai-patch proqramında aşkarlanmış OS command injection zəifliyidir. Xiaomi ağıllı dinamiklərinə təsir edir — uzaqdan hücumçu /mute və /unmute endpoint-ləri vasitəsilə sistemdə ixtiyari əmrlər icra edə bilər. Dərhal yamaq tətbiq olunmalı və ya təsirlənmiş cihazlar şəbəkədən təcrid edilməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which devices are affected by CVE-2026-72580?
This OS command injection vulnerability impacts Xiaomi smart speakers.
How can an attacker exploit CVE-2026-72580?
A remote attacker can execute arbitrary commands on the system via the /mute and /unmute endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.