S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-18371 Scanner

CVE-2019-18371 scanner - Directory Traversal vulnerability in Xiaomi Mi WiFi R3G

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
6
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-18371
7.5
CVSS

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Xiaomi Mi WiFi R3G is a popular Wi-Fi router that is used by many people worldwide. It is designed to provide high-speed internet connection and offers a range of features, including parental control, ad-blocking, and more. The device is primarily intended for home and small office use and is known for its reliability and ease of use.

However, recent reports suggest that the Xiaomi Mi WiFi R3G device is vulnerable to a critical security issue, called CVE-2019-18371. This vulnerability allows an attacker to perform directory traversal attacks and read arbitrary files on the system. By exploiting this vulnerability, an attacker can bypass authentication and gain unauthorized access to the device.

If exploited, this vulnerability can lead to a range of consequences, including data theft, network infiltration, and system compromise. Attackers can use the access to spy on the user and steal sensitive information, such as passwords, credit card details, and other personal data. Moreover, once the attacker gains control over the device, they can use it as a launchpad for further attacks on other devices on the network.

At s4e.io, we understand the importance of cybersecurity and the need for continuous monitoring of digital assets. We offer a range of pro features that can help users quickly identify vulnerabilities in their systems and take corrective action. By using our platform, users can stay informed and keep their digital assets safe from cyber threats. With our easy-to-use interface and comprehensive security insights, our users can rest assured that their online assets remain secure. Stay safe, stay aware!

 

REFERENCES

Solution Advice

To protect against this vulnerability on Xiaomi Mi WiFi R3G, users can take the following precautions:

  • Update to the latest firmware version that includes a fix for this vulnerability
  • Disable the HTTP service on the router and only use HTTPS
  • Change the default admin username and password to a strong and unique one
  • Set up a strong Wi-Fi password and enable WPA3 encryption

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.