CVE-2023-26321 is a critical path traversal vulnerability in the international version of the Xiaomi File Manager application, allowing attackers to overwrite and execute arbitrary code due to unfiltered special characters. With a CVSS score of 9.8, it presents a severe risk as it can be exploited remotely without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high FAUCET Risk Score of 79/100 indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1-210567CPE matchmatch criteria | cpe:2.3:a:mi:file_manager:1-210567:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.