MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows listing, reading, writing, and deleting files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.
The PASS command handler in the SwiFTP server unconditionally grants access regardless of the provided username and password — any combination of login credentials is accepted. A network attacker can send any strings as authentication data, and the FTP server will log them in without verification. This violates both proper implementation of authentication mechanism (CWE-303) and enforcement of access control (CWE-862).
An attacker gains unauthorized access to the FTP server and can freely list, read, write, and delete files shared by the server, leading to disclosure or loss of data stored on the device.
The MiCode/Explorer project has reached end-of-life status — the manufacturer does not plan to release a patch. It is recommended to immediately stop using the built-in SwiFTP FTP server and uninstall the application or replace it with an actively maintained alternative file manager. As a temporary measure, network access to the FTP port used by the application should be blocked using a firewall or network isolation of the device.
MiCode FileExplorer (Xiaomi FileExplorer) with the built-in SwiFTP FTP server component. The MiCode/Explorer project has reached end-of-life status and will not receive further security updates.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XXiaomi Fileexplorer
APPXiaomiall versions