CVE-2019-18370
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.
Se detectó un problema en los dispositivos Xiaomi Mi WiFi R3G versiones anteriores a 2.28.23-estable. El archivo de copia de seguridad está en formato tar.gz. Después de cargar, la aplicación utiliza el comando tar zxf para descomprimir, de modo que se puede controlar el contenido de los archivos en el directorio descomprimido. Además, el script sh de la aplicación para probar las velocidades de carga y descarga lee una lista de URL desde el archivo /tmp/speedtest_urls.xml, y se presenta un vulnerabilidad de inyección de comandos, como es demostrado por api/xqnetdetect/netspeed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-23 CVE Reserved
- 2019-10-23 CVE Published
- 2023-09-29 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC/blob/master/remote_command_execution_vulnerability.py | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mi Search vendor "Mi" | Millet Router 3g Firmware Search vendor "Mi" for product "Millet Router 3g Firmware" | < 2.28.23 Search vendor "Mi" for product "Millet Router 3g Firmware" and version " < 2.28.23" | - |
Affected
| in | Mi Search vendor "Mi" | Millet Router 3g Search vendor "Mi" for product "Millet Router 3g" | - | - |
Safe
|