
Prova de conceito de vulnerabilidade reformulada de https://github.com/utmost3/cve/issues/2 Não levo crédito pela descoberta da vulnerabilidade. Isto é apenas para fins educacionais e de portfólio.
Prova de conceito de vulnerabilidade para a injeção de RCE via pin bluetooth CVE-2026-6992 refeito a partir de https://github.com/utmost3/cve/issues/2 Não levo crédito pela descoberta da vulnerabilidade. Isso é apenas para fins educacionais e de portfólio. Para dispositivos que não possuem gerenciamento por meio de recursos bluetooth, este PoC pode não funcionar. As solicitações JNAP são complicadas.
Este exploit deve funcionar em roteadores MR9600 com recursos bluetooth
usage: CVE-2026-6992-PoC.py [-h] -ti TARGETIP [-tp TARGETPORT] -lp LISTENPORT -li LISTENIP [-u USERNAME] [-p PASSWORD] [-s]
options:
-h, --help show this help message and exit
-ti, --targetIP TARGETIP
Target IP address of the vulnerable router
-tp, --targetPort TARGETPORT
Listening port for the administrative interface, defualts to 80
-lp, --listenPort LISTENPORT
Listening port on the testers machine
-li, --listenIP LISTENIP
IP address that is listening, usually 192.168.1.1
-u, --username USERNAME
Administrator username to be used, defaults to admin
-p, --password PASSWORD
Password for the administrator account, defaults to admin
-s, --https Use https instead of http, http is most common listening protocol on MR9600