CVE-2024-41992
Last modified
CVE-2024-41992 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. EPSS estimates a 2.55% chance of exploitation in the next 30 days.
Description
Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-41992?
How severe is CVE-2024-41992?
How do I fix CVE-2024-41992?
Are you affected by CVE-2024-41992?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
