{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2019-6447/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:estrongs:es_file_explorer:*:*:*:*:*:android:*:*","cpe:2.3:a:estrongs:es_file_explorer_file_manager:*:*:*:*:*:android:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2019-6447"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ES File Explorer File Manager (\u003c= 4.1.9.7.4)"],"_cs_severities":["high"],"_cs_tags":["android","vulnerability","mobile","cve-2019-6447"],"_cs_type":"advisory","_cs_vendors":["Estrongs"],"content_html":"\u003cp\u003eCVE-2019-6447 is a high-severity vulnerability affecting ES File Explorer File Manager for Android (versions 4.1.9.7.4 and earlier). The application improperly initializes an unauthenticated HTTP server on TCP port 59777 immediately upon startup. This server remains active as long as the application process is running in the background or foreground. An attacker present on the same local Wi-Fi network can interface with this service to issue commands in JSON format via HTTP POST requests without any authentication. This vulnerability allows for unauthorized discovery of system and user data, exfiltration of sensitive files including photos, videos, and documents, and the ability to launch installed applications. Given the widespread installation of the application, this flaw poses a significant risk to the privacy and security of mobile device data when connected to untrusted or shared local networks.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe victim launches the ES File Explorer application, which automatically initializes an HTTP server on TCP port 59777.\u003c/li\u003e\n\u003cli\u003eThe attacker performs network scanning (e.g., using nmap or similar) to identify open TCP port 59777 on local network devices.\u003c/li\u003e\n\u003cli\u003eThe attacker determines the device IP address of the target hosting the vulnerable service.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted HTTP POST request to the target IP on port 59777 with a JSON body containing a command (e.g., {\u0026quot;command\u0026quot;:\u0026quot;listFiles\u0026quot;}).\u003c/li\u003e\n\u003cli\u003eThe application service executes the command without authentication, responding with the requested data.\u003c/li\u003e\n\u003cli\u003eThe attacker iterates through specific commands (e.g., listPics, listVideos) to discover targets for exfiltration.\u003c/li\u003e\n\u003cli\u003eThe attacker performs an HTTP GET request to a specific file path identified in the discovery phase to exfiltrate the file content.\u003c/li\u003e\n\u003cli\u003eThe final objective is the exfiltration of sensitive user data or unauthorized control over installed applications.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete exfiltration of personal data, including photos, videos, audio recordings, and documents, from the device. Attackers can also enumerate installed applications and trigger the execution of specific apps, potentially leading to unauthorized usage or exploitation of further device-side vulnerabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify devices within the organization's mobile fleet that have ES File Explorer (version 4.1.9.7.4 or earlier) installed.\u003c/li\u003e\n\u003cli\u003eEnforce mobile device management (MDM) policies to uninstall or block the usage of vulnerable versions of the application.\u003c/li\u003e\n\u003cli\u003eAdvise users to avoid connecting mobile devices to unknown or shared public Wi-Fi networks where this vulnerability is easily reachable by malicious actors.\u003c/li\u003e\n\u003cli\u003eEnsure all mobile applications are updated to the latest available versions, as developers may have patched or removed the problematic management port.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T05:10:48Z","date_published":"2026-09-01T05:10:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-esfileexplorer-cve-2019-6447/","summary":"CVE-2019-6447 allows unauthenticated attackers on a local Wi-Fi network to execute arbitrary commands and exfiltrate files from Android devices running vulnerable versions of ES File Explorer.","title":"Unauthenticated Remote Access Vulnerability in ES File Explorer","url":"https://feed.craftedsignal.io/briefs/2026-09-esfileexplorer-cve-2019-6447/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2019-6447","version":"https://jsonfeed.org/version/1.1"}