WiFi Mouse (Mouse Server) by Necta LLC relies on client-side authentication, which can be trivially bypassed. This flaw allows an attacker on the same network to bypass authentication and potentially achieve remote code execution on the system running the Mouse Server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small operational exploit package for WiFi Mouse Server 1.7.8.5 RCE. Structure is simple: README.md explains the attack flow and operator setup; expliot.py is the primary exploit; powercat.ps1 is a bundled third-party PowerShell networking utility used as the post-exploitation payload. The Python script connects to the target over TCP port 1978, abuses the WiFi Mouse protocol to open cmd.exe on the victim, and injects keystrokes one character at a time using protocol messages. It then types and executes a PowerShell one-liner that downloads powercat.ps1 from an attacker-controlled HTTP server and immediately invokes powercat to spawn a reverse cmd shell back to the attacker on TCP/443. The exploit is unauthenticated and relies on protocol-level command/keystroke injection rather than memory corruption. The included powercat.ps1 is not the vulnerability trigger itself; it is a generic post-exploitation utility that provides reverse shell, listener, relay, and DNS tunneling features, though in this repository it is specifically used for an in-memory reverse shell. Overall, this is a real exploit PoC with a working payload chain, tuned for lab use where certutil-based droppers may be blocked.
This repository contains a Python exploit script (cve-2022–3218.py) and a README.md with usage instructions. The exploit targets a service running on TCP port 1978 on a Windows system, exploiting CVE-2022-3218. The attack involves connecting to the target, opening a command shell, and using certutil.exe to download a malicious payload (typically a reverse shell executable) from an attacker-controlled HTTP server. The payload is saved to C:\Windows\Temp and executed, providing the attacker with remote access. The README provides step-by-step instructions for generating the payload, serving it via HTTP, running the exploit, and setting up a listener to catch the reverse shell. The exploit is operational, requiring the attacker to prepare the payload and infrastructure, but automates the exploitation process once configured.
This repository contains a single Metasploit module (wifi_mouse_rce.rb) that exploits an authentication bypass vulnerability (CVE-2022-3218) in the WiFi Mouse (Mouse Server) application by Necta LLC. The exploit targets Windows systems running vulnerable versions (1.8.3.4 and 1.8.2.3) of the server, which listens on TCP port 1978. The module connects to the server, opens a command prompt (cmd.exe), and types out a payload (by default, a reverse shell), achieving remote code execution as the user running the server. The exploit leverages the fact that authentication is only enforced on the client side, allowing unauthenticated attackers to execute arbitrary commands. The code is written in Ruby and is fully integrated into the Metasploit framework, supporting customizable payloads and automated command staging. The only file in the repository is the exploit module itself.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.