Minerbabe through V4.16 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores