9.8

CVE-2022-3218

Exploit

Necta WiFi Mouse (Mouse Server) client-side authentication bypass

Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NectaWifi Mouse Server Version1.7.8.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 73.48% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-603 Use of Client-Side Authentication

A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

http://packetstormsecurity.com/files/168509/WiFi-Mouse-1.8.3.4-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py
Third Party Advisory
Exploit
https://github.com/rapid7/metasploit-framework/pull/16985
Patch
Third Party Advisory
https://www.exploit-db.com/exploits/49601
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/50972
Third Party Advisory
Exploit
VDB Entry