A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.
References
| Link | Resource |
|---|---|
| https://github.com/pastcompute/tichome-poc-1 | Exploit Third Party Advisory |
| https://web.archive.org/web/20171202094530/ | Not Applicable |
Configurations
Configuration 1 (hide)
| AND |
|
History
05 Mar 2026, 18:13
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/pastcompute/tichome-poc-1 - Exploit, Third Party Advisory | |
| References | () https://web.archive.org/web/20171202094530/ - Not Applicable | |
| First Time |
Mobvoi tichome Mini Firmware
Mobvoi Mobvoi tichome Mini |
|
| CPE | cpe:2.3:o:mobvoi:tichome_mini_firmware:012-18853:*:*:*:*:*:*:* cpe:2.3:h:mobvoi:tichome_mini:-:*:*:*:*:*:*:* cpe:2.3:o:mobvoi:tichome_mini_firmware:027-58389:*:*:*:*:*:*:* |
04 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-78 |
04 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-04 16:16
Updated : 2026-03-05 18:13
NVD link : CVE-2026-26478
Mitre link : CVE-2026-26478
CVE.ORG link : CVE-2026-26478
JSON object : View
Products Affected
mobvoi
- tichome_mini
- tichome_mini_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
