CVE-2019-6447

HIGH

ES File Explorer File Manager < 4.1.9.7.4 - Unauthenticated Arbitrary File Read via TCP Port 59777

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 18 public exploits for CVE-2019-6447. PoCs published by Nehal Zaman, fs0c131y, Chethine, including Metasploit module auxiliary/scanner/http/es_file_explorer_open_port.

AI-analyzed exploit summary This exploit leverages an arbitrary file read vulnerability in ES File Explorer via an exposed HTTP service on port 59777. It allows listing files, retrieving device info, and downloading arbitrary files without authentication.

Description

The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.

Exploits (18)

exploitdb WORKING POC
by Nehal Zaman · pythonremoteandroid
https://www.exploit-db.com/exploits/50070

This exploit leverages an arbitrary file read vulnerability in ES File Explorer via an exposed HTTP service on port 59777. It allows listing files, retrieving device info, and downloading arbitrary files without authentication.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer v4.1.9.7.4
No auth needed
Prerequisites: Target device with ES File Explorer running and exposed HTTP service on port 59777 · Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 677 stars
by fs0c131y · poc
https://github.com/fs0c131y/ESFileExplorerOpenPortVuln

This repository contains a functional PoC for CVE-2019-6447, which exploits an open port (59777) in ES File Explorer to execute commands, retrieve files, and gather device information via JSON payloads. The PoC demonstrates various capabilities, including file retrieval, app launching, and device enumeration.

Classification
Working Poc 100%
Attack Type
Info Leak | Rce
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer (versions 4.1.9.7.4 and below)
No auth needed
Prerequisites: Attacker must be on the same local network as the victim · ES File Explorer must be running on the victim's device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by Chethine · poc
https://github.com/Chethine/EsFileExplorer-CVE-2019-6447

This repository contains a Python-based PoC for CVE-2019-6447, which exploits an unauthenticated HTTP server running on port 59777 in ES File Explorer for Android. The exploit allows remote attackers on the same Wi-Fi network to list files, retrieve device information, and download arbitrary files without authentication.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer 4.1.9.7.4
No auth needed
Prerequisites: Victim must have ES File Explorer 4.1.9.7.4 installed and launched at least once · Attacker must be on the same Wi-Fi network as the victim
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by krbtgt0 · poc
https://github.com/krbtgt0/CVE-2019-6447

This repository contains a functional Python script that exploits CVE-2019-6447, a vulnerability in ES File Explorer's open port (59777) allowing unauthorized file access and device information retrieval. The script sends JSON commands to the vulnerable endpoint to list files, apps, and download arbitrary files without authentication.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer (versions prior to fix for CVE-2019-6447)
No auth needed
Prerequisites: Target device with ES File Explorer running and port 59777 exposed · Network access to the target device
devstral-2 · analyzed Jun 06, 2026 Full analysis →
nomisec WORKING POC 1 stars
by shadowedcreds · poc
https://github.com/shadowedcreds/CVE-2019-6447

This repository contains a functional exploit for CVE-2019-6447, targeting ES File Explorer's open port vulnerability. The Python script interacts with the exposed HTTP API on port 59777 to list files, applications, and device information, as well as download arbitrary files from the affected device.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer (versions prior to fix for CVE-2019-6447)
No auth needed
Prerequisites: Network access to the target device's exposed port (59777) · ES File Explorer running with the vulnerable service enabled
devstral-2 · analyzed May 24, 2026 Full analysis →
nomisec WORKING POC 1 stars
by Nehal-Zaman · poc
https://github.com/Nehal-Zaman/CVE-2019-6447

This PoC exploits CVE-2019-6447, an open port vulnerability in ES File Explorer, allowing unauthorized access to files and device information via HTTP requests. The script interacts with the exposed API to list files, apps, and download arbitrary files without authentication.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer (versions with open port vulnerability)
No auth needed
Prerequisites: Target device with ES File Explorer running and port 59777 exposed · Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
gitlab WORKING POC
by Intek13x · poc
https://gitlab.com/Intek13x/ESFileExplorerOpenPortVuln

This repository contains a functional Python-based PoC for CVE-2019-6447, which exploits an open HTTP server on port 59777 in ES File Explorer. The exploit allows remote command execution to retrieve device information, list files, and launch applications on vulnerable Android devices.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer (versions 4.1.9.7.4 and below)
No auth needed
Prerequisites: Attacker must be on the same local network as the victim
devstral-2 · analyzed Feb 23, 2026 Full analysis →
nomisec WORKING POC
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2019-6447

This exploit targets ES File Explorer 4.1.9.7.4 via an open port vulnerability (CVE-2019-6447) to perform arbitrary file reads and device info enumeration. It interacts with the exposed HTTP service on port 59777 to execute commands like file listing and downloading.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer v4.1.9.7.4
No auth needed
Prerequisites: Target device with ES File Explorer 4.1.9.7.4 installed and the vulnerable service exposed on port 59777
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by KaviDk · poc
https://github.com/KaviDk/CVE-2019-6447-in-Mobile-Application

This repository contains a README describing research on CVE-2019-6447 in a mobile application, with a link to an external video demonstration. No exploit code or technical details are provided.

Classification
Writeup 30%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified mobile application
No auth needed
Prerequisites: access to the referenced video for exploitation details
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by vino-theva · poc
https://github.com/vino-theva/CVE-2019-6447

The repository contains a README describing a vulnerability in ES File Manager for Android (CVE-2019-6447), which involves an open TCP port allowing backdoor installation and data exfiltration. No actual exploit code is provided, only a reference to download PDFs for further details.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: ES File Manager (Android)
No auth needed
Prerequisites: Network access to the vulnerable Android device · Open TCP port exposed by ES File Manager
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by Osuni-99 · poc
https://github.com/Osuni-99/CVE-2019-6447

The repository contains only a README.md file with a brief description of CVE-2019-6447, mentioning an investigation into ES File Browser security weaknesses. No exploit code or technical details are provided.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: ES File Browser
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by VinuKalana · poc
https://github.com/VinuKalana/CVE-2019-6447-Android-Vulnerability-in-ES-File-Explorer

This repository contains only a README file describing CVE-2019-6447, a vulnerability in ES File Explorer for Android. No exploit code or technical details are provided.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: ES File Explorer (version not specified)
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by febinrev · poc
https://github.com/febinrev/CVE-2019-6447-ESfile-explorer-exploit

This exploit targets CVE-2019-6447, an open port vulnerability in ES File Explorer v4.1.9.7.4. It sends crafted JSON commands to the exposed HTTP server on port 59777 to execute actions like listing files, apps, or downloading files.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer v4.1.9.7.4
No auth needed
Prerequisites: Target device with ES File Explorer v4.1.9.7.4 installed and exposed on the network
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by julio-cfa · poc
https://github.com/julio-cfa/POC-ES-File-Explorer-CVE-2019-6447

This is a bash script PoC for CVE-2019-6447, an arbitrary file read vulnerability in ES File Explorer 4.1.9.7.4. It uses curl to send crafted POST requests to the exposed HTTP server on port 59777, allowing unauthorized access to files and system information.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer 4.1.9.7.4
No auth needed
Prerequisites: Target device with ES File Explorer 4.1.9.7.4 installed and exposed on the network · Network access to the target device on port 59777
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by 小荷才露尖尖角, moonbocal, fs0c131y, h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/es_file_explorer_open_port.rb

This Metasploit module exploits an open port vulnerability in ES File Explorer (CVE-2019-6447) to interact with its HTTP server, allowing unauthorized access to device files, apps, and system information. It sends JSON commands to the server and processes responses to enumerate or retrieve data.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ES File Explorer versions 4.1.9.7.4 and below
No auth needed
Prerequisites: Target device must have ES File Explorer installed and running · HTTP server on port 59777 must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/fs0c131y/ESFileExplorerOpenPortVuln
Third Party Advisory x_refsource_misc
https://twitter.com/fs0c131y/status/1085460755313508352

Scores

CVSS v3 8.1
EPSS 0.6202
EPSS Percentile 99.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-306
Status published
Products (1)
estrongs/es_file_explorer_file_manager < 4.1.9.7.4
Published Jan 16, 2019
Tracked Since Feb 18, 2026