PoC Archive PoC Archive

tag

Bluetooth

  • CVE-2026-6992 network HIGH

    MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)

    MR9600 routers with Bluetooth management capability expose a vulnerable JNAP request path that allows command injection via the Bluetooth PIN configuration flow, enabling an attacker to execute arbitrary commands on the router. The PoC reverses the original…

    Unverified 2026-07-05
  • CVE-2023-45866 network HIGH 8.8

    BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)

    BlueDucky is a practical PoC implementation for CVE-2023-45866. It automates Bluetooth device discovery/selection and then emulates HID keyboard input to inject attacker-controlled DuckyScript payloads on vulnerable nearby targets. Because the pairing…

    Patched 2026-05-15