Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.
References
Configurations
No configuration.
History
18 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-18 22:16
Updated : 2026-02-19 15:53
NVD link : CVE-2026-27182
Mitre link : CVE-2026-27182
CVE.ORG link : CVE-2026-27182
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
