Settings

Theme

Mongoose: Preauth RCE and MTLS Bypass on Devices

evilsocket.net

2 points by evilsocket 9 days ago · 1 comment

Reader

evilsocketOP 9 days ago

Mongoose network library <= 7.20

CVE-2026-5244 - mg_tls_recv_cert pubkey heap-based overflow (exploitable), CVE-2026-5245 - mDNS Record stack-based overflow (exploitable), CVE-2026-5246 - authorization bypass via P-384 Public Key (trivially exploitable)

Fun ride.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection