CVE-2021-47851
CRITICALMini Mouse 9.2.0 - Unauthenticated Remote Code Execution via /op=command Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47851. PoCs published by gosh.
AI-analyzed exploit summary This exploit targets Mini Mouse 9.2.0 by sending two JSON payloads to execute arbitrary commands. The first downloads a payload via certutil.exe, and the second executes it, achieving remote code execution.
Description
Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script commands.
Exploits (1)
This exploit targets Mini Mouse 9.2.0 by sending two JSON payloads to execute arbitrary commands. The first downloads a payload via certutil.exe, and the second executes it, achieving remote code execution.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H