Description
Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script commands.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Credits
gosh
References
www.exploit-db.com/exploits/49743 (ExploitDB-49743)
apps.apple.com/us/app/mini-mouse-remote-control/id914250948 (Mini Mouse Apple Store)
www.vulncheck.com/...sories/mini-mouse-remote-code-execution (VulnCheck Advisory: Mini Mouse 9.2.0 - Remote Code Execution)