CyberSec.Space Logo
返回 CVE 浏览器

CVE-2019-18370

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0730%
EPSS Percentile29.65th
Published2019年10月23日
Last Modified2024年11月21日

Vulnerability Description

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.

Affected Platforms (CPE)

💻
Mi

Millet Router 3g Firmware

< 2.28.23

References & Advisories

相关漏洞威胁