The AT&T U-verse 9.2.2h0d83 firmware for Arris NVG589 and NVG599 devices exposes an unauthenticated proxy service on WAN TCP port 49152 when IP Passthrough mode is not enabled. This service allows remote attackers to establish arbitrary TCP connections to internal network hosts by sending a specific byte sequence (\x2a\xce\x01) followed by predictable values, effectively bypassing network segmentation and firewall protections.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is the official Metasploit Framework, a comprehensive and modular exploitation platform widely used for penetration testing, vulnerability research, and red teaming. The structure includes configuration files, code for the core framework (primarily in Ruby), data files for exploits and payloads, and various templates and test files. The framework supports a wide range of exploit modules targeting network services, local privilege escalations, and client-side vulnerabilities. It also includes auxiliary modules for information gathering, credential harvesting, and post-exploitation. The presence of files such as 'data/eicar.com' (antivirus test file), 'data/emailer_config.yaml' (for phishing/email attacks), and LDAP query templates demonstrates support for diverse attack scenarios. The repository is highly mature, weaponized, and designed for extensibility, allowing users to select and configure modules and payloads for specific targets and attack vectors. No specific CVEs or products are targeted in the provided file set, but the framework contains modules for hundreds of vulnerabilities. The main entry points are the Rakefile, Dockerfile, and configuration scripts, which initialize and run the framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.