CVE-2019-13321 is a high-severity vulnerability affecting Xiaomi Browser prior to version 10.4.0, specifically within its handling of HTTP responses to the Captive Portal. An attacker can exploit this by setting up a malicious access point, causing the browser to open a specified URL without user interaction, which can then be chained with other vulnerabilities for arbitrary code execution. The CVSS score of 8.0 (High) reflects its network-adjacent attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.4.0CPE matchmatch criteria | cpe:2.3:a:mi:mi_browser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.