### [CVE-2022-45477](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45477) ![](https://img.shields.io/static/v1?label=Product&message=Telepad&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-306%3A%20Missing%20Authentication%20for%20Critical%20Function&color=brighgreen) ### Description Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H ### POC #### Reference - https://www.synopsys.com/blogs/software-security/cyrc-advisory-remote-code-execution-vulnerabilities-mouse-keyboard-apps/ #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/M507/nmap-vulnerability-scan-scripts - https://github.com/nomi-sec/PoC-in-GitHub