Lucene search

K
cvelistMitreCVELIST:CVE-2019-18371
HistoryOct 23, 2019 - 8:02 p.m.

CVE-2019-18371

2019-10-2320:02:12
mitre
www.cve.org
6

AI Score

7.7

Confidence

High

EPSS

0.031

Percentile

91.2%

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks…/etc/config/account. With this vulnerability, the attacker can bypass authentication.

AI Score

7.7

Confidence

High

EPSS

0.031

Percentile

91.2%

Related for CVELIST:CVE-2019-18371