← Back

CVE-2019-18370

nvd nist
Published: Oct 23, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.

Affected (1)

1 product
Millet Router 3g Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.28.23
Running on/withPlatform Versions
Mi
Millet Router 3g
All versions

Timeline

No history available yet.