Executive brief
MiCode FileExplorer, an open-source file management application, contains a critical security flaw in its built-in FTP server component. This vulnerability allows anyone on the same network to access the device's files without a valid username or password. An attacker could remotely view, download, modify, or delete sensitive data stored on the affected device. As this project is no longer maintained, no official fix is expected.
Technical details
An authentication bypass vulnerability exists in the SwiFTP FTP server component embedded within MiCode FileExplorer. The flaw resides in the PASS command handler, which fails to validate credentials and unconditionally grants access regardless of the username or password provided. A remote, unauthenticated attacker can exploit this over the network to gain full access to the FTP service, enabling them to list, read, write, and delete files on the host system. The MiCode/Explorer project is currently end-of-life (EOL), and no patches are available.
Affected products
- MiCode FileExplorer All versions (End-of-Life)
Timeline
- 2026-03-11: advisory: Initial disclosure by VulnCheck and NVD