Description
Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.
INFO
Published Date :
2024-11-11T00:00:00.000Z
Last Modified :
2024-11-12T17:16:19.610Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2024-41992 vulnerability.
| Vendors | Products |
|---|---|
| Wi-fi-test Suite |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-41992.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact