Vulnerability record · CVE-2019-18371 · published 23 October 2019
CVE-2019-18371: Xiaomi Mi WiFi R3G NGINX alias misconfiguration allows directory traversal file read
MMi · Millet Router 3g Firmware
Xiaomi Mi WiFi R3G firmware before 2.28.23-stable misconfigures an NGINX alias, allowing directory traversal to read arbitrary files. The flaw bypasses authentication, so an unauthenticated network attacker can reach sensitive files such as /etc/config/account.
Description
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe vulnerability is remotely exploitable without authentication, has a public exploit, and a high EPSS score, though it is not known to be actively exploited in the wild.
What it is
Xiaomi Mi WiFi R3G firmware before 2.28.23-stable misconfigures an NGINX alias, allowing directory traversal to read arbitrary files. The flaw bypasses authentication, so an unauthenticated network attacker can reach sensitive files such as /etc/config/account.
Impact
An attacker can read arbitrary files on the device, including configuration and account data. This exposes credentials and device configuration that can enable further compromise.
Attack surface
Reachable over the network via HTTP requests to the router's web interface, specifically the api-third-party/download/extdisks path. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
A public proof-of-concept exploit exists in the references. The CVE is not listed in CISA KEV, but EPSS is 0.55872 (98.995th percentile), indicating high predicted exploitation activity.
What to do
- Update Xiaomi Mi WiFi R3G firmware to 2.28.23-stable or later.
- If patching is not possible, restrict access to the router's web interface to trusted networks only.
- Disable remote administration and unnecessary third-party download features on the router.
- Monitor for and block HTTP requests containing directory traversal sequences targeting the api-third-party/download/extdisks endpoint.
Detection
- Inspect HTTP request logs for traversal patterns such as '../' in requests to api-third-party/download/extdisks.
- Alert on access to sensitive paths like /etc/config/account via the router's web interface.
- Monitor for anomalous outbound connections from the router that may indicate data exfiltration after file read.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC/blob/master/arbitrary_file_read_vulnerability.py | ExploitThird Party Advisory |
| https://github.com/UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC/blob/master/arbitrary_file_read_vulnerability.py | ExploitThird Party Advisory |
Track CVE-2019-18371 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-18371), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.