CVE-2022-3218
9.8
CRITICAL · CVSS 3.1 · EPSS 74% (pctl 99)
Patch early
EPSS 74% — above the 10% action threshold.
Description
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 74.02% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-603 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-09-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| necta | wifi mouse server |
References
- http://packetstormsecurity.com/files/168509/WiFi-Mouse-1.8.3.4-Remote-Code-Execution.html
- https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py
- https://github.com/rapid7/metasploit-framework/pull/16985
- https://www.exploit-db.com/exploits/49601
- https://www.exploit-db.com/exploits/50972
- http://packetstormsecurity.com/files/168509/WiFi-Mouse-1.8.3.4-Remote-Code-Execution.html
- https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py
- https://github.com/rapid7/metasploit-framework/pull/16985
- https://www.exploit-db.com/exploits/49601
- https://www.exploit-db.com/exploits/50972
→ the Explorer · watch your stack · NVD