CVE-2019-6447
HIGH 8.1EPSS 63.5%
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v2.0
- 4.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:N - EPSS
- 63.53% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2019-01-16
- Updated
- 2024-08-04
Proof-of-concept exploits (25)
- http://packetstormsecurity.com/files/163303/ES-File-Explorer-4.1.9.7.4-Arbitrary-File-Rea…
- fs0c131y/ESFileExplorerOpenPortVuln678★ · 2023-09-28
- Chethine/EsFileExplorer-CVE-2019-64473★ · 2022-07-08
- Cmadhushanka/CVE-2019-6447-Exploitation0★ · 2024-07-10
- H3xL00m/CVE-2019-64470★ · 2025-06-05
- KasunPriyashan/CVE-2019_6447-ES-File-Explorer-Exploitation0★ · 2022-07-07
- KaviDk/CVE-2019-6447-in-Mobile-Application0★ · 2022-12-12
- Kayky-cmd/CVE-2019-6447--.0★ · 2024-07-30
- N3rdyN3xus/CVE-2019-64470★ · 2025-06-05
- NyxByt3/CVE-2019-64470★ · 2025-06-05
- Osuni-99/CVE-2019-64470★ · 2022-07-03
- SandaRuFdo/ES-File-Explorer-Open-Port-Vulnerability---CVE-2019-64470★ · 2020-05-14
- Sp3c73rSh4d0w/CVE-2019-64470★ · 2025-06-05
- VinuKalana/CVE-2019-6447-Android-Vulnerability-in-ES-File-Explorer0★ · 2022-06-15
- c0d3cr4f73r/CVE-2019-64470★ · 2025-06-05
- crypticdante/CVE-2019-64470★ · 2025-06-05
- febinrev/CVE-2019-6447-ESfile-explorer-exploit0★ · 2021-10-18
- h3x0v3rl0rd/CVE-2019-64470★ · 2025-06-05
- h3xcr4ck3r/CVE-2019-64470★ · 2025-06-05
- julio-cfa/POC-ES-File-Explorer-CVE-2019-64470★ · 2021-09-13
- k4u5h41/CVE-2019-64470★ · 2025-06-05
- n3ov4n1sh/CVE-2019-64470★ · 2025-06-05
- n3rdh4x0r/CVE-2019-64470★ · 2025-06-05
- vino-theva/CVE-2019-64470★ · 2022-08-02
- xorya1/Exploits-for-Mobile-Evidence-Acquisition3★ · 2024-10-07