Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-41992. PoCs published by fj016.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-41992, demonstrating a command injection vulnerability via crafted TLV packets. The exploit sends a malicious payload to a target device, triggering remote code execution by fetching and executing a script from an attacker-controlled server.
Description
Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.
Exploits (1)
This repository contains a functional exploit for CVE-2024-41992, demonstrating a command injection vulnerability via crafted TLV packets. The exploit sends a malicious payload to a target device, triggering remote code execution by fetching and executing a script from an attacker-controlled server.
References (2)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H