Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5764

29
FAUCET Score

CVE-2020-5764 is a high-severity directory traversal vulnerability affecting MX Player Android App versions prior to v1.24.5, specifically within its "MX Transfer" feature. An attacker can exploit this by sending specially crafted file names containing directory traversal characters, causing files to be saved outside the intended /sdcard/MXshare directory on the victim's device. This can lead to remote code execution in some cases by writing malicious .odex and .vdex files into the application's oat directory. The vulnerability has a CVSS score of 8.8 (HIGH), indicating a network-adjacent attack vector with low complexity and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.24.5CPE matchmatch criteria
cpe:2.3:a:mxplayer:mx_player:*:*:*:*:*:android:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.04%
Probability of exploitation in next 30 days
EPSS Percentile
79.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0204 is in the 88th percentile among its peer group of 1,859 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (8)

esetvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
nxpvendor investigatingvia llm_extracted
omronvendor investigatingvia llm_extracted
openfirevendor investigatingvia llm_extracted
openstackvendor investigatingvia llm_extracted
pnpmvendor investigatingvia llm_extracted
twiliovendor investigatingvia llm_extracted

Vendor Advisories (8)

nxpllm-nxp-f3b526ab344b8adfHIGH

MX Player Android App Directory Traversal

Jul 7, 2020
openstackllm-openstack-31b0f178b09cc650HIGH

MX Player Android App Directory Traversal

Jul 7, 2020
hyperledgerllm-hyperledger-112d767ebc5983f3HIGH

MX Player Android App Directory Traversal

Jul 7, 2020
pnpmllm-pnpm-ae912e0e361ac237HIGH

MX Player Android App Directory Traversal

Jul 7, 2020
omronllm-omron-12a037a2fc05f284HIGH

MX Player Android App Directory Traversal

Jul 7, 2020
twiliollm-twilio-09b5580b8cd393b1HIGH

MX Player Android App Directory Traversal

Jul 7, 2020
openfirellm-openfire-5b5632b8f089d11cHIGH

MX Player Android App Directory Traversal

Jul 7, 2020
esetllm-eset-ed4f07eb6c0d1985HIGH

MX Player Android App Directory Traversal

Jul 7, 2020

References

tenable.com / security/research/tra-2020-41
ExploitThird Party Advisory