Mini Mouse Remote Control Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability exists in Mini Mouse Remote Control version 9.2.0. This issue allows attackers to execute arbitrary commands via an unauthenticated HTTP endpoint. Exploitation involves sending crafted JSON requests with malicious script commands to the '/op=command' endpoint, enabling the download and execution of payloads.
Impact
Exploitation of this vulnerability allows for remote code execution on the affected system.
Reproduction
To reproduce this vulnerability, send a POST request to the '/op=command' endpoint with a JSON payload that includes a command to download a file from a remote server and execute it. The 'script' field of the JSON payload must be crafted to include the desired command, such as using 'certutil' to download a file and 'start' to execute it.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
