CVE-2019-9599
HIGHAirDroid < 4.2.1.6 - Denial of Service via sdctl/comm/lite_auth Requests
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-9599. PoCs published by s4vitar.
AI-analyzed exploit summary This script exploits a Denial of Service (DoS) vulnerability in AirDroid by flooding the target with HTTP requests to the '/sdctl/comm/lite_auth/' endpoint, causing system crash and forced reboot. It uses curl in a loop to send 10,000 concurrent requests per iteration.
Description
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.
Exploits (2)
This script exploits a Denial of Service (DoS) vulnerability in AirDroid by flooding the target with HTTP requests to the '/sdctl/comm/lite_auth/' endpoint, causing system crash and forced reboot. It uses curl in a loop to send 10,000 concurrent requests per iteration.
This repository contains a Python-based exploit for CVE-2019-9599, targeting AirDroid to steal device information and perform DoS attacks. It includes scripts for scanning, information theft, and denial-of-service.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H