CVE-2026-26478 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 4, 2026
Mobvoi Tichome Mini - Command Injection
Published: March 4, 2026Updated: March 4, 2026Remote Exploitable
Overview
Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 contains a command injection caused by processing of specially crafted UDP datagrams, letting remote attackers execute arbitrary shell code as root, exploit requires network access.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Remote attackers can execute arbitrary shell commands as root, leading to full system compromise.
Mitigation
Update to the latest version or apply vendor patches addressing this vulnerability.
Related Resources
Details
- CVE ID
- CVE-2026-26478
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- unconfirmed
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H