Exploitation Summary
EIP tracks 4 public exploits for CVE-2023-31902.
PoCs published by Chokri Hammedi, lypd0, xl337x, including Metasploit module exploits/windows/misc/mobile_mouse_rce.
AI-analyzed exploit summary This exploit demonstrates a Remote Code Execution (RCE) vulnerability in Mobile Mouse 3.6.0.4 by sending crafted network packets to trigger arbitrary command execution via a file download and execution sequence.
Description
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
Exploits (4)
This exploit demonstrates a Remote Code Execution (RCE) vulnerability in Mobile Mouse 3.6.0.4 by sending crafted network packets to trigger arbitrary command execution via a file download and execution sequence.
This exploit targets CVE-2023-31902, a remote code execution vulnerability in Mobile Mouse 3.6.0.4. It leverages the protocol's lack of authentication to send crafted packets that download and execute a payload via the Windows Run dialog, using a fresh TCP session to ensure reliable execution.
The repository contains a functional exploit for CVE-2023-31902, targeting Mobile Mouse 3.6.0.4. The exploit leverages unauthenticated command injection via a crafted TCP socket payload to achieve remote code execution (RCE) on the target system.
This Metasploit module exploits CVE-2023-31902 in Mobile Mouse Server by RPA Technologies, Inc., allowing remote code execution on unprotected servers (default configuration without a password). It leverages the server's protocol to deploy and execute a payload via a staged approach using certutil.exe.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H