CVE-2022-45482

CRITICAL

lazy_mouse < 2.0.1 - Unauthenticated Remote Code Execution via Weak PIN Brute Force

Title source: llm
STIX 2.1

Description

Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scores

CVSS v3 9.8
EPSS 0.0130
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-521
Status published
Products (1)
lazy_mouse_project/lazy_mouse < 2.0.1
Published Dec 02, 2022
Tracked Since Feb 18, 2026