Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-18371

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.906
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-18371


Contact Us

Shodan ® - All rights reserved