CVE-2026-26478Disclosure(mobvoi / tichome_mini)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tichome_mini
  • tichome_mini_firmware

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
tichome_minitichome_mini_firmware

3 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-04: 4Technical Details · 2026-03-04: 403-04
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26478 A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram … https://www.cve.org/CVERecord?id=CVE-2026-26478 ----- Traducción: CVE-2026-26478 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026‑26478, a shell command injection flaw in Mobvoi Tichome Mini smart speakers that permits remote attackers to send crafted UDP datagrams; no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000033
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26478 A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram … https://www.cve.org/CVERecord?id=CVE-2026-26478

    Post summary

    A shell command injection flaw (CVE‑2026‑26478) has been disclosed for Mobvoi Tichome Mini smart speakers, enabling remote attackers to exploit via crafted UDP packets.

    00000198
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26478 - Critical A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary... https://www.thehackerwire.com/vulnerability/CVE-2026-26478/ https://t.co/CnAzoXNVpr

    Post summary

    A critical shell command injection vulnerability (CVE-2026-26478) has been disclosed for Mobvoi Tichome Mini smart speakers, enabling remote command execution via crafted UDP datagrams.

    0000049
    121 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26478 Shell Command Injection in Mobvoi Tichome Mini Smart Speaker Enables Root Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26478

    Post summary

    The text announces a new shell command injection vulnerability in the Mobvoi Tichome Mini Smart Speaker that can lead to root code execution, providing technical details but no evidence of exploitation, PoC, or patch.

    0000050
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
HWmobvoitichome_mini---
OSmobvoitichome_mini_firmware012-18853--
OSmobvoitichome_mini_firmware027-58389--

Explore more