CVE-2019-11380: Estrongs Es File Explorer File Manager

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading to remote FTP access to the entirety of local storage.

Affected products

  • Estrongs Es File Explorer File Manager: version 4.2.0.1.3 only

Published 2019-09-05. Last modified 2026-06-17.