Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.
https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=547