CVE-2022-3218
critical · 9.8Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
9.8
CVSS
74.0%
EPSS (exploit prob.)
99th
EPSS percentile
2022-09-19
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-603CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| necta | wifi_mouse_server | 1.7.8.5 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/168509/WiFi-Mouse-1.8.3.4-Remote-Code-Execution.html
- https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py
- https://github.com/rapid7/metasploit-framework/pull/16985
- https://www.exploit-db.com/exploits/49601
- https://www.exploit-db.com/exploits/50972
- http://packetstormsecurity.com/files/168509/WiFi-Mouse-1.8.3.4-Remote-Code-Execution.html
- https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py
- https://github.com/rapid7/metasploit-framework/pull/16985
- https://www.exploit-db.com/exploits/49601
- https://www.exploit-db.com/exploits/50972
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-3218