Vulnerability record · CVE-2022-3218 · published 19 September 2022
CVE-2022-3218: WiFi Mouse Server client-side authentication bypass leads to RCE
Necta · Wifi Mouse Server
WiFi Mouse (Mouse Server) from Necta LLC relies on client-side authentication, so its authentication mechanism can be trivially bypassed. A bypassed attacker can then reach functionality that results in remote code execution. The flaw is remotely reachable without credentials, making it serious for any host running the server.
Description
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code and a Metasploit module available, and a very high EPSS score.
What it is
WiFi Mouse (Mouse Server) from Necta LLC relies on client-side authentication, so its authentication mechanism can be trivially bypassed. A bypassed attacker can then reach functionality that results in remote code execution. The flaw is remotely reachable without credentials, making it serious for any host running the server.
Impact
An unauthenticated remote attacker gains code execution on the machine running WiFi Mouse Server, giving full control of that host. This can lead to data theft, further lateral movement, or use of the host as a foothold.
Attack surface
Reached over the network via the WiFi Mouse Server service; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication and no user interaction are required. The description does not specify the exact port or protocol details.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.74016, 99.458th percentile) and multiple references are tagged Exploit, including public PoC code and a Metasploit pull request, indicating public exploitation tooling exists.
What to do
- Patch or update WiFi Mouse Server to a fixed version if the vendor provides one; the record does not name a fixed version, so verify with Necta LLC.
- If no fix is available, remove or disable WiFi Mouse Server on hosts that do not require it.
- Restrict network access to the WiFi Mouse Server port to trusted hosts only, using host firewalls or network segmentation.
- Do not expose the service to untrusted networks or the internet.
- Monitor for and block the known public exploit code and Metasploit module activity against this service.
Detection
- Monitor network traffic to the WiFi Mouse Server port for unexpected or unauthorized clients, especially from outside expected management segments.
- Alert on process creation or command execution spawned by the WiFi Mouse Server process.
- Search for the public PoC script names or Metasploit module artifacts in logs, file systems, or network signatures.
- Baseline normal WiFi Mouse Server client connections and alert on new or anomalous source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168509/WiFi-Mouse-1.8.3.4-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/16985 | PatchThird Party Advisory |
| https://www.exploit-db.com/exploits/49601 | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/50972 | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/168509/WiFi-Mouse-1.8.3.4-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/16985 | PatchThird Party Advisory |
| https://www.exploit-db.com/exploits/49601 | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/50972 | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2022-3218 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2022-3218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.