CVE-2019-6447

HIGH

Estrongs ES File Explorer File Manager - Missing Authentication

Title source: rule

Description

The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.

Exploits (16)

exploitdb WORKING POC
by Nehal Zaman · pythonremoteandroid
https://www.exploit-db.com/exploits/50070
nomisec WORKING POC 677 stars
by fs0c131y · poc
https://github.com/fs0c131y/ESFileExplorerOpenPortVuln
nomisec WORKING POC 2 stars
by Chethine · poc
https://github.com/Chethine/EsFileExplorer-CVE-2019-6447
nomisec WORKING POC 1 stars
by Nehal-Zaman · poc
https://github.com/Nehal-Zaman/CVE-2019-6447
gitlab WORKING POC
by Intek13x · poc
https://gitlab.com/Intek13x/ESFileExplorerOpenPortVuln
nomisec WORKING POC
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2019-6447
nomisec NO CODE
by Kayky-cmd · poc
https://github.com/Kayky-cmd/CVE-2019-6447--.
nomisec NO CODE
by Cmadhushanka · poc
https://github.com/Cmadhushanka/CVE-2019-6447-Exploitation
nomisec WRITEUP
by KaviDk · poc
https://github.com/KaviDk/CVE-2019-6447-in-Mobile-Application
nomisec WRITEUP
by vino-theva · poc
https://github.com/vino-theva/CVE-2019-6447
nomisec WRITEUP
by Osuni-99 · poc
https://github.com/Osuni-99/CVE-2019-6447
nomisec WRITEUP
by VinuKalana · poc
https://github.com/VinuKalana/CVE-2019-6447-Android-Vulnerability-in-ES-File-Explorer
nomisec WORKING POC
by febinrev · poc
https://github.com/febinrev/CVE-2019-6447-ESfile-explorer-exploit
nomisec WORKING POC
by julio-cfa · poc
https://github.com/julio-cfa/POC-ES-File-Explorer-CVE-2019-6447
nomisec NO CODE
by SandaRuFdo · poc
https://github.com/SandaRuFdo/ES-File-Explorer-Open-Port-Vulnerability---CVE-2019-6447
metasploit WORKING POC
by 小荷才露尖尖角, moonbocal, fs0c131y, h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/es_file_explorer_open_port.rb

Scores

CVSS v3 8.1
EPSS 0.7126
EPSS Percentile 98.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-306
Status published
Products (1)
estrongs/es_file_explorer_file_manager < 4.1.9.7.4
Published Jan 16, 2019
Tracked Since Feb 18, 2026