Back

CVE-2019-18370

CRITICAL

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.

Published: Oct 23, 2019 Modified: Jun 17, 2026
CWE-78

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
mi millet_router_3g_firmware * < 2.28.23

GitHub Security Advisory GHSA-353j-pfv3-ppx7

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 40.29%

Top 1% most likely to be exploited

Threat Score 51.3 / 100

Data Sources

NVD EPSS GitHub