CVE-2019-18370
Last modified
CVE-2019-18370 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. EPSS estimates a 40.29% chance of exploitation in the next 30 days.
Description
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mi | Millet Router 3g Firmware | < 2.28.23 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-18370?
How severe is CVE-2019-18370?
How do I fix CVE-2019-18370?
Are you affected by CVE-2019-18370?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
