CVE-2026-57082

MEDIUM

Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-57082. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-57082, a cryptographic weakness in Net::BitTorrent versions through 2.0.1 for Perl. The module outlines the vulnerability (non-cryptographic PRNG used for MSE Diffie-Hellman private key generation) but lacks actual exploit implementation, instead providing placeholder warnings and TODOs.

Description

Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator seeded once per process, in KeyExchange.pm. The shared secret and the RC4 keys derived from it (the SHA-1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on a predictable PRNG. The same handshake sends, in cleartext, random padding drawn from the same rand() sequence in _random_pad, immediately after the public key and the private-key draw. A passive observer of the handshake recovers the PRNG state from the cleartext padding, reconstructs the private key, computes the shared secret from the peer's public key on the wire, derives the RC4 keys, and decrypts the connection, defeating the passive-observation obfuscation MSE provides.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-57082_netbittorrent_versions_through.py

This repository contains an auto-generated stub module for CVE-2026-57082, a cryptographic weakness in Net::BitTorrent versions through 2.0.1 for Perl. The module outlines the vulnerability (non-cryptographic PRNG used for MSE Diffie-Hellman private key generation) but lacks actual exploit implementation, instead providing placeholder warnings and TODOs.

Classification
Stub 98%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Net::BitTorrent (Perl) versions through 2.0.1
No auth needed
Prerequisites: Target must be running a vulnerable version of Net::BitTorrent · Network access to the BitTorrent port (default: varies)
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 5.9
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-330 CWE-338
Status published
Products (2)
SANKO/Net::BitTorrent < 2.0.1
SANKO/Net::BitTorrent < 2.1.0
Published Jun 30, 2026
Tracked Since Jun 30, 2026