Vulnerability Details CVE-2026-26478
A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 80.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-26478
-
cpe:2.3:h:mobvoi:tichome_mini:-
-
cpe:2.3:o:mobvoi:tichome_mini_firmware:012-18853
-
cpe:2.3:o:mobvoi:tichome_mini_firmware:027-58389