A buffer overflow vulnerability exists in IQ Engine versions prior to 10.6r2 on Extreme Network AP devices. The flaw is due to improper bounds checking, allowing an attacker to overwrite memory beyond the intended buffer limits.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working proof-of-concept exploit for CVE-2023-35803, an unauthenticated remote code execution vulnerability affecting ARM-based Extreme Networks/Aerohive Wireless Access Points running HiveOS/IQ Engine versions below 10.6r2. The exploit consists of a Python script (poc.py) that crafts and sends a specially constructed payload to the target device's management service on TCP port 5916. The payload leverages a stack-based buffer overflow and ROP chain to execute an arbitrary shell command on the device. The intended command downloads and executes a reverse shell script (revshell), which, when run, creates a PHP webshell and initiates a reverse shell connection to the attacker's machine (default port 1337). The README provides clear usage instructions, including how to set up the reverse shell listener and host the payload. The repository is operational and demonstrates a full exploit chain from unauthenticated access to remote shell, with all necessary components included.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.