CVE-2016-10646 describes a Man-in-the-Middle (MITM) vulnerability in the resourcehacker Node.js package, which wraps the Resource Hacker Windows executable. The vulnerability arises because resourcehacker downloads binary resources over unencrypted HTTP, allowing an attacker to intercept and replace the requested binary. This could lead to remote code execution (RCE) if an attacker, positioned between the user and the remote server, swaps the legitimate binary with a malicious one. The vulnerability has a CVSS v3 score of 8.1 (High), indicating a high-impact threat with network access, high confidentiality, integrity, and availability impacts, but requiring high attack complexity. Its EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:resourcehacker_project:resourcehacker:-:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.