A CRLF injection vulnerability exists in Dropbear SSH prior to version 2016.72, where remote authenticated users can inject carriage return and line feed characters into X11 forwarding data. This allows them to bypass intended shell-command restrictions, potentially executing unauthorized commands on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Python exploit script (main.py) targeting CVE-2016-3116, a vulnerability in Dropbear SSH's X11 forwarding implementation. The exploit leverages the paramiko library to connect to a target SSH server and abuses the X11 forwarding mechanism to inject crafted authentication cookies and commands. This allows the attacker to read arbitrary files (such as /etc/passwd), write data to files, and execute X11-related commands on the target system. The script provides an interactive shell for issuing exploit commands, and includes demo SSH keys for testing. The rest of the repository consists of IDE configuration files and does not contribute to the exploit functionality. The exploit is a proof-of-concept and requires valid SSH credentials (password or private key) and X11 forwarding to be enabled on the target. No hardcoded network endpoints are present, but file paths such as /etc/passwd and /home/user/.ssh/authorized_keys are used as examples of attack targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.