Mini Mouse Remote Control Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists in Mini Mouse Remote Control version 9.2.0. This issue allows attackers to execute arbitrary commands via an unauthenticated HTTP endpoint. Exploitation involves sending crafted JSON requests with malicious script commands to the '/op=command' endpoint, enabling the download and execution of payloads.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Reproduction

To reproduce this vulnerability, send a POST request to the '/op=command' endpoint with a JSON payload that includes a command to download a file from a remote server and execute it. The 'script' field of the JSON payload must be crafted to include the desired command, such as using 'certutil' to download a file and 'start' to execute it.

Added: Jan 21, 2026, 6:27 PM
Updated: Jan 21, 2026, 6:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.3
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.