Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4hf-7q6p-whw3

Опубликовано: 19 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.

EPSS

Процентиль: 32%
0.00126
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.4
nvd
4 месяца назад

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.

EPSS

Процентиль: 32%
0.00126
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-306