CVE-2019-18371
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 56%
from disclosure to weapon0 days
Published on NVDOct 23
1st PoCAug 30
VulnCheck+1898d
exploitation probability
56%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.
Affected products
n/a · n/apublic PoCs found — 1
vulncheckvulncheck.com/xdb/750ba4d5e0baunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.