A vulnerability in the AirDroid Android application through version 4.2.1.6 allows remote attackers to cause a denial of service by sending a large number of simultaneous requests to the sdctl/comm/lite_auth/ endpoint. This results in the service crashing due to resource exhaustion.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a multi-stage exploit toolkit targeting AirDroid (CVE-2019-9599), specifically versions 4.2.1.6 and earlier, running on Android devices. The exploit chain is as follows: 1. **Discovery (AirDroidPwner.py):** Uses the Shodan API to enumerate public IPs with AirDroid service exposed on port 8888. It checks which hosts are active and writes the list to a file named 'ips'. 2. **Information Extraction (AttackHost.py, AttackHosts.py):** These scripts send crafted requests to the AirDroid service. If the user on the device accepts the connection, the scripts extract sensitive information such as battery level, SMS count, contacts, multimedia content, OS version, device model, and location. They also attempt to dump the contact list. 3. **Denial of Service (airdroid_dos.sh, airdroid_fast_dos.sh):** Bash scripts that send a flood of requests to the AirDroid service, aiming to exhaust device resources and crash the application or the device itself (Remote DoS/System Crash). 4. **Web Management (web_browser.py):** Opens all discovered AirDroid endpoints in the default web browser for manual interaction. The exploit requires a valid Shodan API key for initial target enumeration. The attack vector is network-based, targeting devices with AirDroid exposed to the internet. The endpoints of interest are HTTP services on port 8888, specifically the '/sdctl/comm/lite_auth/' path. The toolkit automates both reconnaissance and exploitation, and can be used for both targeted and mass attacks. The README provides detailed usage instructions and describes the vulnerability and its impact. The exploit is operational, with working code for both information theft and denial of service, but does not include a full bypass for the client-side acceptance dialog (the user must accept the connection for information theft to succeed). The DoS component does not require user interaction.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.