CVE-2020-35173: Amaze File Manager Project Amaze File Manager

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP server (aka services.ftpservice.FTPReceiver.ACTION_START_FTPSERVER and services.ftpservice.FTPReceiver.ACTION_STOP_FTPSERVER).

Affected products

Published 2020-12-30. Last modified 2026-06-17.