CVE-2019-6447 is a vulnerability in ES File Explorer File Manager for Android (up to version 4.1.9.7.4) where the application opens TCP port 59777 on the local Wi-Fi network after being launched. This port accepts unauthenticated HTTP requests with application/json data, allowing remote attackers on the same network to read arbitrary files or execute applications on the device without user interaction or authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small Python research harness for CVE-2019-6447 affecting ES File Explorer File Manager on Android. It is not just documentation: it contains working client code and a CLI that can probe the target service, send unauthenticated JSON commands, and retrieve files over HTTP from a vulnerable device. The implementation is intentionally scoped to a single user-specified target and avoids subnet scanning. Repository structure: README.md and docs/technical-analysis.md provide vulnerability background, protocol notes, impact, and safe-lab guidance. pyproject.toml defines the package and exposes the esfile-6447 console script. The main logic is in src/esfile6447/client.py and src/esfile6447/cli.py. Tests in tests/test_cli.py and tests/test_client.py use a loopback mock HTTP server rather than a real device. Main exploit capabilities: (1) probe() performs a raw TCP connectivity check to the configured host and port, defaulting to 59777; (2) command() sends HTTP POST requests to / with JSON containing a top-level command field and optional appPackageName, enabling service-specific interaction such as getDeviceInfo and appLaunch; (3) pull_file() performs HTTP GET against an attacker-supplied absolute path, enabling arbitrary file read from locations accessible to the ES File Explorer process, then writes the response to a local output path. The CLI gates command and pull operations behind a local acknowledgment flag, but this is only a safety feature in the tool and not part of the target-side exploit. Network/protocol behavior: the client constructs a base URL of http://<host>:<port>, uses POST / with Content-Type application/json for command dispatch, and GET /<path> for file retrieval. The default port is TCP/59777, matching public descriptions of the vulnerable embedded HTTP service. The code sets a custom User-Agent and enforces short timeouts and basic error handling. Overall assessment: this is a legitimate exploit/research client for an adjacent-network unauthenticated service exposure. It is more than a detector because it includes active exploitation primitives for command invocation and file retrieval, but it remains a relatively restrained PoC/operational harness rather than a weaponized framework.
This repository contains a Python exploit script (exploit.py) targeting CVE-2019-6447, a vulnerability in ES File Explorer version 4.1.9.7.4 for Android. The exploit abuses an open HTTP server running on port 59777, which is exposed by the ES File Explorer app. The script allows an attacker to send various commands to the target, including listing files, pictures, videos, audios, installed apps, and downloading arbitrary files from the device. It can also retrieve device information. The exploit requires the attacker to specify the command, target IP, and (for file download) the full path of the file to retrieve. The README.md provides a brief description and screenshots, while the main logic resides in exploit.py. The attack vector is network-based, requiring access to the target's port 59777. The endpoints of interest are the HTTP server on the target device and the file paths specified for download.
This repository contains a single Metasploit auxiliary scanner module targeting ES File Explorer's open HTTP port vulnerability (CVE-2019-6447) on Android devices. The module exploits the unauthenticated HTTP server (default port 59777) exposed by ES File Explorer versions 4.1.9.7.4 and below. It provides multiple actions, including listing files, pictures, videos, audio, installed apps, system apps, phone apps, APKs on the SD card, retrieving device information, downloading arbitrary files, and launching apps remotely. The module interacts with the target by sending crafted HTTP POST and GET requests to the exposed port. The exploit is operational and can be used to exfiltrate sensitive data or perform further actions on vulnerable Android devices running the affected app. The code is written in Ruby and is structured as a standard Metasploit module.
This repository provides a proof-of-concept (POC) exploit for CVE-2019-6447, a vulnerability in ES File Explorer (Android app) versions 4.1.9.7.4 and below. The vulnerability exposes a local HTTP server on port 59777, allowing unauthenticated attackers on the same local network to send crafted HTTP requests to the device. The main exploit script, 'poc.py', is a Python tool that can scan a network or target a specific host, sending commands to enumerate files, retrieve device information, list installed apps, pull files or APKs, launch apps, and extract app icons from the victim's device. The script uses the 'requests' library to interact with the HTTP server and provides a command-line interface for various attack actions. The repository also includes a README.md with detailed usage instructions, example commands, and a list of supported actions. The exploit does not provide a weaponized payload but demonstrates the full range of information and files that can be exfiltrated from a vulnerable device. The only code file is 'poc.py', which serves as the entry point for the exploit. The attack vector is network-based, requiring the attacker to be on the same LAN as the victim. Several example file paths and endpoints are provided in the documentation and code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.