The Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4 contains an undocumented shell command 'prompt' that allows a user to set the shell's prompt value. This value is then used directly as a format string input to printf, leading to a classic format string vulnerability. This can result in the disclosure of memory addresses and potentially other sensitive information, depending on the format string used.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Small repository with 3 files: two Markdown documents and one Python exploit script. The main code is exploit.py, a standalone Python Telnet exploit that connects to a target on TCP/23, waits for a 'login:' prompt, submits hardcoded credentials ('admin' / 'password'), and then sends format-string payloads through a 'prompt' command. The first payload uses repeated %p specifiers to leak memory addresses; the second uses %n (%2500c%35$n) to attempt an arbitrary write and possible control-flow hijack. The script then sends 'exit' and 'reboot', suggesting an attempt to trigger the corrupted state or complete the exploit chain. The code is incomplete/malformed near the end, but its intended capability is clear and offensive rather than diagnostic. README.md documents CVE-2019-7711 as a format-string information leak in the Green Hills INTEGRITY RTOS 5.0.4 IPCOMShell/Telnet service, describing exploitation via Telnet and unsafe printf handling. Use.md appears to discuss a different Telnet-related memory corruption concept involving SLC triplets and buffer geometry; it does not match the Python exploit directly and looks like supplemental or mixed research notes rather than code used by exploit.py. Overall, this repository is a proof-of-concept/operational exploit repo targeting a network-accessible Telnet service, primarily focused on memory disclosure and attempted write-primitive exploitation against Green Hills INTEGRITY RTOS-related Telnet functionality.
The repository is very small and consists of a README plus a single Python entry-point script, exploit.py. The script is a standalone network exploit targeting CVE-2019-7711 in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. It is not part of a larger exploit framework. Operationally, the exploit uses telnetlib to connect to a user-supplied target on TCP/23, waits for a 'login:' prompt, and authenticates with hardcoded credentials ('admin' / 'password'). It then sends a format-string payload through the IPCOMShell 'prompt' command. Phase 1 attempts a broad memory disclosure using repeated %p, %x, and %s specifiers, followed by additional shell commands ('pwd', 'show tasks', 'help') to generate output that is then read back and printed for manual analysis. Phase 2 sends a fixed write payload ('%2500c%35$n') intended to exercise a %n arbitrary-write primitive. Phase 3 sends 'exit' and 'reboot' as trigger commands in an attempt to activate corrupted state or hijacked control flow. The code demonstrates exploit intent beyond simple detection, but it remains relatively basic and partially manual: offsets are hardcoded, leak analysis is left to the operator, and the parsed --lhost/--lport options are unused, so there is no implemented reverse shell or second-stage payload. As written, it is best characterized as an operational PoC for remote TELNET-based format-string exploitation against a vulnerable maintenance interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.