❌

Normal view

Received β€” 2 April 2026 ⏭ /r/netsec - Information Security News & Discussion

Mongoose: Preauth RCE and mTLS Bypass on Millions of Devices

Mongoose network library <= 7.20

CVE-2026-5244 - mg_tls_recv_cert pubkey heap-based overflow (exploitable)
CVE-2026-5245 - mDNS Record stack-based overflow (exploitable)
CVE-2026-5246 - authorization bypass via P-384 Public Key (trivially exploitable)

Fun ride.

submitted by /u/evilsocket
[link] [comments]
❌