CVE-2022-45482 is a critical vulnerability affecting the Lazy Mouse server, allowing remote, unauthenticated attackers to easily brute-force the PIN due to weak password requirements and a lack of rate limiting. This flaw enables arbitrary command execution with a CVSS score of 9.8 (Critical), indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community and media attention, including articles from BleepingComputer and SecurityWeek highlighting its potential for remote code execution in widely installed Android remote keyboard apps.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.1CPE matchmatch criteria | cpe:2.3:a:lazy_mouse_project:lazy_mouse:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.