CVE-2019-18371
https://notcve.org/view.php?id=CVE-2019-18371
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication. Se detectó un problema en los dispositivos Xiaomi Mi WiFi R3G versiones anteriores a 2.28.23-estable. • https://github.com/UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC/blob/master/arbitrary_file_read_vulnerability.py • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2019-18370
https://notcve.org/view.php?id=CVE-2019-18370
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed. Se detectó un problema en los dispositivos Xiaomi Mi WiFi R3G versiones anteriores a 2.28.23-estable. • https://github.com/UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC/blob/master/remote_command_execution_vulnerability.py • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2019-15843
https://notcve.org/view.php?id=CVE-2019-15843
A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle attack may lead to partial data leakage or malicious file writing. Se detectó una vulnerabilidad de carga de archivos maliciosa en los teléfonos móviles Xiaomi Millet versión 1-6.3.9.3. Una condición particular que involucra un ataque de tipo man-in-the-middle puede conducir a una fuga parcial de datos o escritura de archivos maliciosos. • https://sec.xiaomi.com/post/152 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2019-13321 – Xiaomi Browser Captive Portal WebView Authorization Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2019-13321
This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw exists within the handling of HTTP responses to the Captive Portal. A crafted HTML response can cause the Captive Portal to to open a browser to a specified location without user interaction. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. • https://www.zerodayinitiative.com/advisories/ZDI-19-659 • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2019-13322 – Xiaomi Browser miui.share APK Download Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2019-13322
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the miui.share application. The issue results from the lack of proper validation of user-supplied data, which can result in an arbitrary application download. An attacker can leverage this vulnerability to execute code in the context of the user. • https://www.zerodayinitiative.com/advisories/ZDI-19-660 • CWE-20: Improper Input Validation CWE-356: Product UI does not Warn User of Unsafe Actions •