Junglewise Threat Intelligence

CVE-2026-72580: Xiaomi xiaoai-patch OS command injection in speaker API

CVE-2026-72580 · Severity: critical · CVSS 9.8 · Published 2026-08-10

Executive brief

A patching tool for Xiaomi smart speakers contains an OS command injection vulnerability in its web API endpoints that allow remote attackers to execute arbitrary system commands on affected devices. An attacker can exploit this through unsanitized query parameters in the mute/unmute endpoints, potentially gaining full control over the speaker and any connected smart home systems.

Technical details

The vulnerability is an OS command injection flaw in the xiaoai-patch project's api/main.py file. The /mute and /unmute endpoint handlers pass the user-supplied "silent" query parameter directly to os.system() without sanitization or validation, allowing shell metacharacters to break out and execute arbitrary commands. The attack vector is network-based and requires only network access to the affected device's API endpoint (no authentication mentioned as required). An attacker can inject shell commands through metacharacters in the query string to achieve remote code execution with the privileges of the patched speaker process. The vulnerability affects xiaoai-patch through commit fb07049.

Affected products

  • Xiaomi xiaoai-patch through commit fb07049

Timeline

  • 2026-08-10: disclosed

References