CVE-2019-6447
58Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 64%
from disclosure to weapon0 days
Published on NVDJan 16
1st PoCJan 9
metasploitJan 16
exploitation probability
64%top 1% of all CVEs
observed exploitation
nono source reports it
15 public exploit(s)
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
Affected products
n/a · n/apublic PoCs found — 15
exploitdbwww.exploit-db.com/exploits/50070unverifiedgithubgithub.com/fs0c131y/ESFileExplorerOpenPortVuln★ 678githubgithub.com/Chethine/EsFileExplorer-CVE-2019-6447★ 3githubgithub.com/Kayky-cmd/CVE-2019-6447--.★ 0githubgithub.com/VinuKalana/CVE-2019-6447-Android-Vulnerability-in-ES-File-Explorer★ 0githubgithub.com/Osuni-99/CVE-2019-6447★ 0githubgithub.com/vino-theva/CVE-2019-6447★ 0githubgithub.com/KaviDk/CVE-2019-6447-in-Mobile-Application★ 0githubgithub.com/acloudinthebluesky/CVE-2019-6447-ES-File-Explorer★ 0githubgithub.com/SandaRuFdo/ES-File-Explorer-Open-Port-Vulnerability---CVE-2019-6447★ 0githubgithub.com/Cmadhushanka/CVE-2019-6447-Exploitation★ 0githubgithub.com/julio-cfa/POC-ES-File-Explorer-CVE-2019-6447★ 0githubgithub.com/febinrev/CVE-2019-6447-ESfile-explorer-exploit★ 0githubgithub.com/h3x0v3rl0rd/CVE-2019-6447★ 0cve_referencepacketstormsecurity.com/files/163303/ES-File-Explorer-4.1.9.7.4-Arbitrary-File-Read.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.