Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-13054

Description

The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.

POC

Reference

No PoCs from references.

Github

- https://github.com/10ocs/LOGITaker-

- https://github.com/OwenKruse/LOGITackerMouseComplete

- https://github.com/OwenKruse/LOGITackerRawHID

- https://github.com/OwenKruse/LogiNew

- https://github.com/OwenKruse/Logitacker-Mouse

- https://github.com/RoganDawes/LOGITacker

- https://github.com/RoganDawes/munifying

- https://github.com/RoganDawes/munifying-web

- https://github.com/mame82/UnifyingVulnsDisclosureRepo

- https://github.com/mame82/munifying_pre_release